This isn't what an autonomous agent is. Without a private environment for it to run in, the best you get are not-even half-measures of observing the thing that are trivially defeatable by a human running a script