You are running code you did not write. It might be an AI agent executing an

LLM's output, a CI job running npm install across dependencies nobody audited,

or a plugin that insists it needs shell access. A normal container does almost

nothing for you here. It is namespaces and cgroups, and the full kernel attack

surface is still sitting right there. Every runc escape CVE is the reminder.