The Paranoid Guide to Running Copilot CLI in a Secure Docker Sandbox