It's currently allowed and users can run shell commands in the container. Should we disallow calling `execute_command_line`, even considering #46?