Optional Material: Running on macOS using a Non Priveleged Account
While not as secure as using Docker or Apple Containers, I often set up a new account on my Mac without admin priveleges and no access to my iCloud account (so sensitive financial or medical data in, for example, ~/Documents is not accessible).
I consider this to be an approach for partial security and but I use it when experimenting with Hermes Agent, little-coder, etc.
If you want tighter security, then use the material in the following chapter on Apple Containers.
Dear reader, decide for yourself how secure you want your use of agentic coding to be.