Run AI coding agents (Claude Code, OpenCode) safely inside sandboxed Docker containers with audit logging