You are running code you did not write. It might be an AI agent executing an
LLM's output, a CI job running npm install across dependencies nobody audited,
or a plugin that insists it needs shell access. A normal container does almost
nothing for you here. It is namespaces and cgroups, and the full kernel attack
surface is still sitting right there. Every runc escape CVE is the reminder.







