Yeah, you're right. This tool was something I wrote to control unintentional leaks that I observed when working on something at my internship. While writing this I did try accounting for things like ssh, systemd-run and using D-Bus to run other processes but I wasnt really able to think of a way to stop this type of leak.
Also there's not much I can do to stop a dedicated LLM from getting out if its intention is to escape containment beyond maybe like a sandbox with no network access and access to these daemons. I appreciate the comment though, I really should update the readme to mention this.