Coop is now verifiable beyond the echo: it is an open-source repository under the GitHub org of Trail of Bits, the application-security research firm, described as 'a Rust CLI that manages disposable virtual machines where Claude Code and Codex have full tool access: Docker, git, compilers, package managers, all without risk to your host machine,' with each VM 'isolated, reproducible, and cheap to create and destroy.' The README shows a build-from-source path (Rust + CMake), a 'coop setup' command that builds a VM template image, and a companion 'coop-proxy' binary, and the repo carries SECURITY.md plus a docs/trust-model.md framed as 'the engineering-facing trust model for coop — the authoritative list of trust boundaries.' The supplied snippets do not establish which VM technology it uses, the specifics of its network or credential controls, any escape testing or independent review, or adoption. Note: the earlier 'no internet access' association traces to a separate Trail of Bits benchmark methodology (agents run in offline Docker containers for their challenge evals), not to Coop itself. This satisfies the case's own reheat condition of 'direct repo verification,' with the trust-model document directly addressing the standing open question about containment guarantees.
2026-09-28T22:52:49Z
SpaceO (1/1) stretches the tracked containment pattern to the display layer with no Coop content, making this the third consecutive look adding only marginal periphery after Kern and Augur. With the Trail of Bits repo verified, docs/trust-model.md published, and independent implementations crowding the field, VM-level containment for coding agents is established knowledge rather than an open episode — the case closes absorbed and survives as a standing SiloOS/Bubblewrap comparison artifact; Coop-specific escape testing, findings, or adoption would re-enter via the hot agent-sandboxing concept.
2026-09-28T21:36:33Z
evidence attached: reddit.post.1wsqb4y — Virtual-display isolation for computer-use agents materially extends the containment-boundary pattern the Coop case tracks, from VMs to the display layer.
2026-09-28T14:35:04Z
Kern Sandbox is one more low-signal addition to the crowded containment periphery with no Coop content, so the case's meaning is unchanged; I promote it to corroborated on the verified Trail of Bits repo plus independent user testimony, and park it at low heat as a standing SiloOS/Bubblewrap comparison candidate. The magnitude-valve spread reading remains the ambient sandboxing pattern rather than this episode — Coop-specific velocity is near zero — so reheating now requires Coop-specific adoption, security findings, or escape testing.
2026-09-28T13:35:16Z
evidence attached: hn.story.49877284 — Released rootless-container sandbox purpose-built for LLM-generated code materially contextualises the containment-boundary landscape the Coop case tracks.
2026-09-27T13:32:20Z
grounded: converges/medium — The verified Trail of Bits repo satisfies the case's own reheat condition and strengthens convergence: a credible security-research firm now ships disposable-VM
2026-09-27T13:25:41Z
Augur adds a second title-only macOS-VM sandbox with no Coop content, so the case's meaning settles: VM-level containment for coding agents is a confirmed but now-crowded and cooling pattern in which Coop remains a single unverified exemplar. Its value to Scott is as a standing SiloOS/Bubblewrap comparison candidate rather than a live episode; I price heat low despite the magnitude-valve reading because the spread is the tracked sandboxing pattern, not Coop — Coop-specific velocity is ~0.17 pts/h with zero comments.
2026-09-27T13:23:46Z
evidence attached: hn.story.49866246 — Independent second macOS-VM sandbox for coding agents, corroborating VM-level containment for coding-agent execution as a spreading pattern.
2026-09-23T18:06:38Z
Drop’s rootless/gVisor announcement and discussion expand the sandbox comparison landscape, including an explicit Bubblewrap comparison, but neither it nor the title-only DiscoBox submission validates Coop. The expanding periphery warrants medium attention; the loud spread reading is driven by adjacent tools rather than independent Coop implementations or adoption.
2026-09-22T20:23:59Z
evidence attached: hn.story.49806850 — Disposable sandboxes materially reinforce the open case that isolated execution is becoming a standard containment boundary for coding agents.
2026-09-22T14:23:55Z
evidence attached: hn.story.49801329 — The released rootless gVisor sandbox provides independent evidence of practical containment alternatives for agent and developer-tool execution.
2026-09-17T13:41:36Z
The newly attached VM-cost submission supplies only a title, not cost figures, methodology, or a Coop comparison, so it does not establish the operating tradeoffs claimed by the attachment rationale. Coop remains an unverified comparison candidate rather than a demonstrated containment or migration option.
2026-09-17T13:22:27Z
evidence attached: hn.story.49740053 — This independent cost analysis materially contextualizes the practicality and operating tradeoffs of VM isolation for coding agents.
2026-09-17T07:29:38Z
The claude-sandbox announcement adds another author-reported coding-agent sandbox, but its supplied excerpt establishes neither VM isolation nor tested containment and provides no independent evidence about Coop. The comparison landscape is expanding without changing Coop’s assessment or establishing a reason for Scott to switch isolation approaches.
2026-09-17T07:22:35Z
evidence attached: reddit.post.1wimfif — This is an independent released sandbox artifact addressing the same VM or host-containment problem for autonomous coding agents.
2026-09-16T15:41:26Z
Agentbox adds an author-reported parallel-agent workflow, not independent validation of Coop or inspected containment evidence. Its explicit copying of OAuth credentials and optional external files highlights why sandbox convenience and security boundaries need separate evaluation, without establishing any Coop defect or advantage.
2026-09-16T15:22:38Z
evidence attached: hn.story.49728120 — An independent released sandboxing workflow provides concrete corroboration that VM or container isolation is becoming a practical boundary for parallel coding agents.
2026-09-16T14:37:09Z
Beltdown adds a title-only allegation about a Claude Code sandbox escape, with no exploit details or demonstrated connection to Coop’s VM boundary. It neither validates Coop as a remedy nor contradicts its containment claims; the case still lacks inspected implementation or security results.
2026-09-16T14:22:54Z
evidence attached: hn.story.49727207 — A reported Claude Code sandbox escape is directly relevant to whether isolation boundaries actually contain coding agents.
2026-09-16T12:25:55Z
WVM adds a title-only discovery lead for Windows agent execution, not verified implementation evidence or independent validation of Coop. Adjacent sandbox announcements continue to accumulate without establishing Coop’s containment guarantees or a reason for Scott to change his current isolation approach.
2026-09-16T12:21:48Z
evidence attached: hn.story.49725680 — A concrete headless Windows execution sandbox for AI agents materially bears on the open VM-containment episode.
2026-09-15T11:22:50Z
The new Docker wrapper offers an author-reported workflow for Claude and Codex, not inspected containment or independent validation of Coop. Adjacent sandbox announcements continue to accumulate without changing Coop’s assessment or establishing a reason for Scott to switch execution-isolation approaches.
2026-09-15T11:22:22Z
evidence attached: hn.story.49710493 — A usable Docker-based sandbox for Claude and Codex provides additional evidence about practical containment for coding-agent execution.
2026-09-15T09:22:53Z
The new Docker-socket item is a title-only allegation about a separate evaluation harness, not verified containment evidence or a finding about Coop. It reinforces the need to inspect exposed host capabilities but does not establish Coop’s guarantees or an advantage over Scott’s current setup.
2026-09-15T09:22:16Z
evidence attached: hn.story.49709608 — Concrete evidence that an ostensibly containerized coding-agent harness exposes an unisolated host Docker socket, challenging assumptions about execution containment.
2026-09-15T08:27:50Z
Brig adds another microVM sandbox discovery lead, but its title-only listing neither establishes practical containment nor independently validates Coop. The broader pattern remains relevant, without new evidence that changes Coop’s assessment or warrants changing Scott’s execution-isolation setup.
2026-09-15T08:21:28Z
evidence attached: hn.story.49709131 — Brig is independent corroboration that microVM isolation is becoming a practical containment pattern for coding-agent execution.
2026-09-15T01:21:45Z
Pi-box adds a claimed VM/WASM/Electron implementation lead, not independent validation of Coop. A commenter’s specific shared-IAM concern about SCH sharpens the distinction between execution isolation and resource authorization, but neither item establishes a change in Coop’s containment or its value versus Scott’s current setup.
2026-09-15T01:21:34Z
evidence attached: hn.story.49706083 — A concrete Pi implementation adds VM, WASM, and Electron isolation to the open question of practical containment boundaries for coding agents.
2026-09-13T21:22:22Z
The SCH listing adds an AWS sandbox discovery lead, not a verified alternative implementation or corroboration of Coop: its title supplies no architecture, containment tests, or actual pricing. The adjacent sandbox coverage still gives Scott no established reason to change his execution-isolation setup.
2026-09-13T21:22:10Z
evidence attached: hn.story.49688741 — An AWS-hosted sandbox offers a materially relevant alternative implementation for isolating coding-agent execution.
2026-09-09T23:34:40Z
The Adios.dev listing adds an adjacent sandbox discovery lead, but its title establishes neither VM architecture nor independent corroboration of Coop’s containment boundary. Coop remains a relevant evaluation target for Scott’s existing sandboxing work, with no new implementation finding or demonstrated reason to change his setup.
2026-09-09T23:22:39Z
evidence attached: hn.story.49635498 — A separate isolated-execution sandbox provides relevant corroboration for VM-level containment of AI-agent workloads.
2026-09-08T23:23:35Z
The macOS sandbox item supplies only a title, not evidence of a concrete deployment outcome or a tested containment boundary, and has no demonstrated connection to Coop. It adds adjacent reading rather than corroboration; Coop remains an evaluation target without a newly established reason to change Scott’s sandboxing setup.
2026-09-08T23:22:32Z
evidence attached: hn.story.49618387 — A concrete macOS sandbox deployment adds relevant evidence about containment boundaries for coding-agent execution, though it is not VM-level isolation.
2026-09-08T17:42:26Z
E2B’s CEO identifies E2B as the VM provider discussed in the adjacent article, adding attributable infrastructure context but no evidence about Coop itself. Coop remains a relevant containment evaluation target; neither its security properties nor a reason to change Scott’s setup is newly established.
2026-09-08T15:38:31Z
The refreshed adjacent discussion raises fleet ownership and filesystem-persistence questions but adds no Coop-specific implementation finding. Coop remains a relevant containment comparison, while repeated discussion of other VM platforms does not independently corroborate its boundary or establish a reason to change Scott’s setup.
2026-09-08T14:37:15Z
The WSL Manager maintainer’s shipped MCP integration adds a concrete adjacent implementation of agent-managed execution environments, not independent corroboration of Coop or its containment guarantees. Coop remains a relevant comparison for Scott’s sandboxing work, with no new Coop-specific finding that warrants promotion or a setup change.
2026-09-08T14:23:02Z
evidence attached: reddit.post.1wapdj1 — Independent corroboration that VM- or distro-level sandboxing is becoming a practical containment pattern for coding agents.
2026-09-08T08:31:11Z
The adjacent article’s author now reports Firecracker and Git-backed memory in other agent platforms, adding architectural context but no demonstrated connection to Coop. Coop remains a containment evaluation target, not an independently validated boundary or a demonstrated improvement over Scott’s existing setup.
2026-09-08T07:32:58Z
The refreshed discussion remains practical-use testimony and comparison questions, not a new implementation finding or independent validation of Coop’s containment boundary. Coop remains worth evaluating against Scott’s existing sandboxing setup, but this delta supplies no reason to change that setup or elevate the case.
2026-09-08T05:25:21Z
The newly attached VM article is adjacent context, not independent corroboration of Coop: its title establishes no connection to Coop or tested containment properties. Coop remains a relevant evaluation target for Scott’s agent sandboxing work, with no new basis for changing his setup.
2026-09-08T05:21:57Z
evidence attached: hn.story.49605644 — Independent coverage adds context on VM architectures powering Claude Code and other agents, strengthening the case’s relevance to agent execution isolation.
2026-09-07T10:29:28Z
The refreshed discussion adds interest in off-the-shelf agent isolation and mentions competing sandboxes, but no new Coop implementation evidence or tested containment properties. Coop remains a relevant comparison target for Scott’s sandboxing work, not yet a demonstrated reason to change his setup.
2026-09-07T09:29:05Z
A commenter’s claimed daily use adds a modest practical-use signal beyond the title-only introduction, specifically for separating agents from unrelated projects and personal files. This supports evaluating Coop, but does not independently establish its VM boundary or security guarantees; the remaining discussion supplies no concrete reason to switch from existing sandboxes.
2026-09-07T04:25:31Z
Coop remains a relevant evaluation target for Scott’s coding-agent containment work, but the repository echo and HN title are one evidence chain, not independent corroboration. This look adds no implementation evidence or consequential delta beyond the previously routed introduction.
2026-09-07T04:24:42Z
grounded: converges/medium — Coop’s reported VM-isolation approach converges narrowly with Scott’s SiloOS execution-containment position and offers a concrete comparison for the Bubblewrap
2026-09-07T04:22:15Z
case created — A concrete owner-hosted artifact offers coding-agent VM isolation distinct from existing containment episodes, though the single title-only observation establishes no security validation.