reject running as root, bind ssh hostfwd to 127.0.0.1 only, reject commas in --mount and claude paths (prevents -virtfs csv injection), pre-check --mount path exists, enable qemu seccomp sandbox.
reject running as root, bind ssh hostfwd to 127.0.0.1 only, reject commas in --mount and claude paths (prevents -virtfs csv injection), pre-check --mount path exists, enable qemu seccomp sandbox.