All the "fun" (untrusted) stuff on that machine is behind the sandboxing of a browser and the OS itself.
Anything that needs local permission is on a separate laptop which is only got one account: Claude. Not even signed in to Apple (nor any browser) on that, despite it being a Mac.
What is to stop even reputed closed source software from shipping a newer release with a malicious feature that ships your personal files it gets access to a remote location?
The best I've got is to have tools like firewalls highlightling any odd behaviours and perhaps the newer decision models like Jev or laya etc trained to spot such anomalies in app behavior and bubble them up for attention - because manually watching or deterministically scripting to catch those is not practical.