Claude Managed Agents Runtime Uses gVisor Sandboxing but Ships Permissive Defaults | HACKOBAR_