It doesn't matter where the models are, that's just a traditional API server. The agent harness is the thing that can read files and make http calls (to exfiltrate) and that's regular software running somewhere else. So one typically puts the harness in a sandbox and puts extra LLM calls in to guardrail (prompt / tool call checks).
I'm planning to do something like this for myself as an OpenCode plugin, but to stop my message and record it for clarity or block angry
I'm planning to do something like this for myself as an OpenCode plugin, but to stop my message and record it for clarity or block angry