I really like this idea. It will be useful for local first users for simple applications. Is it open source? If yes, can you share the link? if not, how can we send templates under our name? are there any template or app marketplace? @bashtian
The interesting benchmark is not merely whether each agent receives a VM. It is whether a compromised task can cross capability, credential, network, or persistence boundaries.
Separate model behavior from system security. Even an unreliable model can be deployed safely if capabilities, egress, credentials, and state transitions are enforced outside it.
This appears less like a classification-capability problem than an incentives and enforcement problem. What measurable abuse-response SLA should an ad platform provide?