Coding agents can expose API keys, OAuth tokens, private keys, and local devices if not properly isolated. The post explains why containers alone are not enough to protect developer secrets and how Docker and similar sandboxing techniques can reduce the risk when running autonomous coding agents.