Currently build steps are running without any kind of sandbox.
It would be nice to restrict the tools to the source folders (i.e. it does not need write access everywhere) and limit the access to specific domains.
Such approach could also be re-used when running AI agents.