Per-workflow isolation
Each tree has its own dependencies. A browsing agent's Playwright install doesn't leak into your email agent's environment.
Reproducible environments
Same config runs the same everywhere. No drift between your machine and a teammate's.
Bounded reach
Each agent can only touch what its container's mounts grant it. Nothing leaks to the host filesystem.
Clean uninstall
Delete the agent — its container and files go with it. Nothing lingers on your system.