I don't want claude code to have access to files outside the workspace. maybe we can combine this with something like: https://github.com/Automata-Labs-team/code-sandbox-mcp