A "slug" is a layer-2 bridge, with no IP address configured, that still enforces a TCP/IP whitelist. So it does not "use" a hop on the network route, and you can't see the device, but as it bridges traffic it enforces a (very simple) ruleset.
In my case, I use my own VPN hosts that transact over TCP22 ... and so my network "slug" allows only tcp port 22 traffic. Everything else is blocked.
This means that no matter how badly behaved (or buggy) my VPN software is (I use sshuttle[1]) the bad behavior is blocked by the slug.
The slug itself has almost zero attack surface as it is a BSD based system that has no IP address configured and runs no network services.
I keep meaning to write up a blog entry about this ...