I barely trust Claude Code as it is, and neither should anyone to run arbitrary commands unless you run it in a strong sandbox.