2026-10-11 17:10 UTC

Trail of Bits presents Coop as isolated VM environments for running Claude Code and Codex, potentially giving builders a VM-level containment boundary for coding-agent execution.

state: resolvedheat: lowuncertainty: lowconvergesscott: mediumagent-sandboxing coding-agents agentic-securityTrail of Bits

What is this?

Coop is now verifiable beyond the echo: it is an open-source repository under the GitHub org of Trail of Bits, the application-security research firm, described as 'a Rust CLI that manages disposable virtual machines where Claude Code and Codex have full tool access: Docker, git, compilers, package managers, all without risk to your host machine,' with each VM 'isolated, reproducible, and cheap to create and destroy.' The README shows a build-from-source path (Rust + CMake), a 'coop setup' command that builds a VM template image, and a companion 'coop-proxy' binary, and the repo carries SECURITY.md plus a docs/trust-model.md framed as 'the engineering-facing trust model for coop — the authoritative list of trust boundaries.' The supplied snippets do not establish which VM technology it uses, the specifics of its network or credential controls, any escape testing or independent review, or adoption. Note: the earlier 'no internet access' association traces to a separate Trail of Bits benchmark methodology (agents run in offline Docker containers for their challenge evals), not to Coop itself. This satisfies the case's own reheat condition of 'direct repo verification,' with the trust-model document directly addressing the standing open question about containment guarantees.

Why it matters to Scott

The verified Trail of Bits repo satisfies the case's own reheat condition and strengthens convergence: a credible security-research firm now ships disposable-VM containment for Claude Code/Codex and publishes docs/trust-model.md as 'the authoritative list of trust boundaries' — independently enacting Scott's Architecture-Not-Vibes position (untrusted agents, structural containment, explicitly documented trust boundaries) and handing him dated receipts plus a concrete trust-model artifact to compare against SiloOS capability controls and Songbird's Bubblewrap Codex workers. Relevance stays medium: the supplied material establishes no adoption, escape testing, or demonstrated reason to switch from his current stack, and Coop-specific heat has already passed.
ip:framework.architecture-not-vibesip:framework.siloosip:concept.sandboxed-executiondev:project.silo-osdev:technology.bubblewrapradar:concept.agent-sandboxingradar:docker-ai-agent-sandboxesradar:concept.coding-agent-securityradar:brig-microvm-agent-containment
queries asked of Scott's wikis
  • coding-agent execution isolation capability controls
  • Bubblewrap sandbox containment for Codex workers
  • VM vs container vs OS-sandbox tradeoffs for agent execution
  • trust boundary / threat-model documentation for agent tooling
  • disposable reproducible environments for parallel coding agents
  • agent network egress control and proxy patterns

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

09-07 04:22 (minted)⭐ origin echo-reconstructedThe linked repository is presented as “Coop – Isolated VM Environments for Running Claude Code and Codex.”
Trail of Bits on github (echo) · attributed from hn.story.49593842 · published time unknown
—
09-07 04:18first on hacker news · published · lag ?Coop – Isolated VM Environments for Running Claude Code and Codex
aggrrrh
—
09-08 14:05first on r/ClaudeAI · published · lag ?Gave Claude Code the whole WSL lifecycle over MCP: create, configure, run and package distros (and Linux VMs on macOS)
bostrot
—
09-07 04:18amplified on hacker newshn.story.49593842
aggrrrh
peak 71 · 16 comments · 21% of case engagement
09-08 04:36amplified on hacker newshn.story.49605644
RohanAdwankar
peak 78 · 27 comments · 25% of case engagement
09-08 14:05amplified on r/ClaudeAIreddit.post.1wapdj1
bostrot
peak 0 · 1 comments · 0% of case engagement
09-08 23:03amplified on hacker newshn.story.49618387
ingve
peak 4 · 0 comments · 1% of case engagement
09-09 22:32amplified on hacker newshn.story.49635498
clovis818
peak 3 · 0 comments · 1% of case engagement
09-13 21:11amplified on hacker newshn.story.49688741
cdani
peak 8 · 5 comments · 3% of case engagement
14 more amplifiers in ainews.case_chain
09-07 04:21our radar first saw it · lag ?discovery anchor: hn.story.49593842—

Evidence (21) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnCoop – Isolated VM Environments for Running Claude Code and Codexaggrrrh7116
🟧 echo.github ⭐The linked repository is presented as “Coop – Isolated VM Environments for Running Claude Code and Codex.”Trail of Bits——
🟧 hnThe VMs Powering Mobile Agents (Instinct, Claude Code)RohanAdwankar7827
🟠 redditGave Claude Code the whole WSL lifecycle over MCP: create, configure, run and package distros (and Linux VMs on macOS)
ClaudeAI
bostrot01
🟧 hnWhat Happens When You Lock Claude in a macOS Sandboxingve40
🟧 hnAdios.dev – Fast, isolated execution sandboxes for AI agentsclovis81830
🟧 hnSCH: An affordable sandbox for Coding Agents in your AWS accountcdani85
🟧 hnShow HN: Pi-box: Pi coding agent running inside a VM inside WASM inside Electronschmuhblaster30
🟧 hnBrig: Run coding agents in a MicroVM sandboxiamsyr10
🟧 hnOpenAI's SWE-bench harness relies on unisolated host Docker socketsamoriz30
🟧 hnShow HN: Bash sandbox script for Claude and codex CLIiwwr10
🟧 hnWVM – A headless Windows 11 execution sandbox for AI agentsandy157110
🟧 hnBeltdown: Escaping the Claude Code Sandboxsnikolaev20
🟧 hnShow HN: Agentbox – Teleport your repo into sandboxes with no worktree jugglingmadarco40
🟠 redditI built claude-sandbox, a free, open-source (Apache 2.0) sandbox for coding agents using claude.
ClaudeAI
gilesknap02
🟧 hnShow HN: What sandboxing an AI coding agent in a VM costsmichael_luog20
🟧 hnShow HN: Drop – a rootless Linux sandbox with gVisor supportmixedbit13647
🟧 hnDiscoBox: AI Coding Agents in Disposable SandboxesTheIronYuppie10
🟧 hnShow HN: Augur – Sandboxed macOS VMs with Xcode for AI Coding Agentsh1d3mun310
🟧 hnShow HN: Kern Sandbox, a rootless container for LLM-generated coderealexweb21
🟠 redditI built SpaceO: give Claude Code its own virtual monitor on your Mac
ClaudeAI
ParthJadhav11

Interpretation history

Decision trace