Don't forget to manage proper permissions for every piece of data your own user account would need acccess to complete the objectives of the agent.
Like in the "Play some jazz music" example in the documentation, don't forget to login to the Music app using your own Apple ID on the new user or VM you created.
I’m not sure a user account would contain the potential damage enough for my liking, and isn’t the point of this to enable it to “act like you” on your personal machine ? (which I maintain is a terrible idea).