I reckon something lie Qubes could work fairly well.
Create a new Qube and have control over network connectivity, and do everything there, at the end copy the work out and destroy it.
Sandboxing the agent hardly seems like a sufficient defense here.