A coding agent reads text written by strangers: issues on your tracker, code from repositories, instructions on web pages. One malicious instruction can make the agent send credentials somewhere it shouldn’t. On a machine-wide VPN, that request leaves the same way as everything else, and afterwards nobody can say which program sent it or where it went.
VPN Works uses Linux network namespaces to seal an agent in its own network. The agent’s only way out is through vpnw itself, so a script that ignores proxy settings finds no route anywhere. Every connection is checked against a policy and logged.
The technical innovation is policy-based isolation without virtualization overhead. A namespace is lightweight—you’re not spinning up containers. You’re carving out a network view that the agent sees but the rest of your system doesn’t. Connections are enforced at the kernel level, so the policy can’t be circumvented by userspace trickery.
Day to day it comes down to four commands. run picks the outbound path and starts the program. trace prints every connection. guard enforces a policy. learn drafts a policy from a traced run.
The technical appeal of learn is that it inverts the security model. Instead of writing a policy from scratch, you observe normal behavior and carve out the exceptions. Under a default-deny policy, a hostname that isn’t allowed is never even looked up by DNS, so DNS itself can’t leak data. Every connection is logged, so you have a record.
There’s a second engine. Scope brings the same idea to the company VPN. It learns from traffic who uses which systems inside your network and drafts least-privilege rules for the gateway.
Both are Alphas, tested on Linux. The live demo replays real runs of an agent trying to leak a token, and you can edit the policy against the real engine, compiled to WebAssembly. How It Works covers the sandbox in detail.
The technical appeal is that security becomes local and observable. You’re not trusting a remote service to enforce policy. You’re enforcing it at the machine where the code runs, and you have a log of every decision. The innovation is making default-deny practical for development without requiring infrastructure expertise or central gatekeeper.