I think you should try docker.io. With this making LXC is extremely easy. Setting up LXC is a one time process, and then you can run it in < 5 sec anytime.
And there is no way a bug or user from inside LXC here can compromise the host. Client LXC has total separation of resources at base level using cgroups and namespaces, not only with the host but other LXCs running on the same host as well.