What still seems unsolved is how to safely use it on real private systems (large codebases, internal tools, etc) where you can’t risk leaking context even accidentally.
In our experience that constraint changes the problem much more than the choice of runtime or SDK.
>...and without permission on any device.
I would be much more interested in a tool which only allows AI to run within the boundaries which I choose and only when I grant my permission.