I have a server that's now my Claude Code development machine, as well as a host server for the various tools I develop. Its only accessible over my tailnet.

I uninstalled Claude Code from my laptop after an incident where it got stuck on an issue and started scanning my home folder for resources. Its unacceptable and scary behavior, so now it gets it own machine where it can't touch my keys.

I moved to sandbox-exec (safehouse) and now I am trying to setup a lightweight container/VM. Though of maintaining a new user but didn't seem like a great idea. How much are you paying that claude worker server?

> I uninstalled Claude Code from my laptop after an incident where it got stuck on an issue and started scanning my home folder for resources.

At the very least, you should create a separate user account, without sudo, for agents. If you do anything risky, a VM seems required.

Or sandbox-exec (or container/VM) with 1. first denay 'everything', then 2. grant access carefully.