f89849801b
Capture the isolated-VM design for the self-modification frontier: Proxmox sandbox clone, network isolation (esp. from tmi-dev/day-job), snapshot-rollback, spend/resource caps, kill switch, human-gated promotion. Build the cage before the agent gets code-write powers. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>