Their general opinion is that this makes Tails less secure as now you have to trust both the host and the visualization software.
Provided that you trust Tails itself. The expected way to run it is off of a live cd. This way the trusted OS is only ever in ram, and if you use a non-rewritable disk you can also be assured that the Tails disk itself cannot be modified after its creation.
Tails handles the 'only talking to Tor' via iptables. Unless I am mistaken Tails' firewall will not allow clearnet connections.
[0] https://tails.boum.org/doc/advanced_topics/virtualization/in...