sitectl set; it writes the override immediately:
composer.json and composer.lock from the Drupal container to the host, which is required when using sitectl drupal composer require, remove, or update to author dependency changes. Use ordinary git commands in the project checkout for branch, remote, and upstream management.
To work through a sandboxed coding agent, add the assistant service:
cli-sandbox service.
Disable dev mode the same way:

