Sandbox + memory + MCP is the right bundle if you’re trying to keep long-horizon agents from collapsing into chat loops. The part I’d watch hardest in production is how memory scoping interacts with the sandbox boundary — once an agent can write outside the sandbox narrative, “MCP tools” become privilege escalation with better DX.