Article: Trail of Bits has open-sourced Coop, a Rust-based command-line tool that spins up disposable virtual-machine sandboxes so AI coding assistants such as Claude Code and OpenAI Codex can run with unrestricted access to Docker, git, compilers and other development utilities—without exposing the host computer.

Why a sandbox is needed

AI-driven code generators are increasingly used to write, refactor and even execute code on a developer’s machine. To be useful they must call the same toolchain a human would, which means they need direct access to the filesystem, network and build tools. That level of access also gives the AI a foothold to download malicious payloads, exfiltrate data or corrupt the host environment. Security teams therefore treat autonomous coding agents as a potential attack surface.

How Coop creates a safe boundary

Coop automates the creation of an isolated virtual machine for each AI session:

  • Disposable VMs – each sandbox spins up on demand and is torn down after use, wiping any compromised state.
  • Full tool access inside the VM – the AI assistant sees the same Docker, git, compiler, and other binaries it would on a regular workstation, so its output stays realistic.
  • Host isolation – the VM runs in a separate kernel instance, keeping any malicious command confined to the guest.
  • Reproducible environment – because the VM image is defined in code, security reviewers can verify exactly what the AI can access each time.

What’s still missing for enterprise use

Coop shows a practical approach to AI safety, but it isn’t a turnkey solution for large organizations. Gaps include:

  • Limited AI provider support – only Claude Code and OpenAI Codex ship out of the box.
  • No built-in policy enforcement – enterprises cannot define custom rules that automatically block certain commands or network calls.
  • Absence of centralized audit logging – there is no native way to aggregate logs from multiple sandboxes for compliance or forensic analysis.

These omissions force security teams to build extra tooling or accept reduced control before deploying Coop at scale.

Who should try it now

Independent developers, hobbyist teams, and security researchers who want to experiment with autonomous coding agents can adopt Coop today. Its open-source nature lets users inspect the code, customize the VM image, and push improvements back to the community.