That's a good idea. Be careful of the more advanced models finding ways to abuse/circumvent it though, even with only a limited set of parameters. Eg. A lot of git commands can be tricked into dropping into less which can drop into a full shell.
They know all the gtfobins.org tricks.
I think they're implying that it's not actually a nation state threat actor, that Russian cyber criminals looking to exploit systems for money are able to act with impunity so long as they don't target Russians (hence "want their bag"). Most incidents are financially motivated.