Could you explain what you mean by a proper hypervisor? I don't see how hypervisors are relevant here.
In that scenario, the model could do whatever it wants in its own environment, unless it managed to break the hypervisor (whether KVM, Xen, ESXi doesn't really change much) any attempt to exploit the proxy would have little value without a hypervisor exploit (earth shattering/sphincter tightening news) as even with the exploited proxy it's still inside another secured environment (provided their networking setup is properly configured). Any actual hypervisor escape is far more challenging/terrifying and also easier to notice straight away.