Why do you believe this to be true?
I don't agree, I use containers via Dagger
> Full network access
Not really a sandbox if the agent can make POST or GET requests to exfiltrate