Enforces OS-level filesystem and network restrictions on arbitrary processes without containers, offering lightweight sandboxing for safely running AI agents and untrusted code.