I originally built this as a way to make it safer to give CLI coding agents more autonomy. I wrote about that particular use case here: https://ammar.io/blog/httpjail.

Any feedback is appreciated!