VPN Works: Lets Agile Teams Run Coding Agents Safely Without Slowing Them Down
Security gates at the end of a sprint kill velocity. A coding agent can cut feature work time in half, but security teams that don’t understand what the agent does will block it. The agent reads code from your repo, issues from your tracker, snippets from web pages, and it writes back pull requests. One malicious instruction planted in that text can make the agent send a deploy token somewhere it shouldn’t. Default-allow is dangerous. Default-deny with a review process is bureaucracy that kills the agile advantage.
VPN Works gives teams the third option: default-deny that doesn’t require a gatekeeper. The tool seals a coding agent in a Linux network namespace whose only way out is through a policy that the team drafted. A script that tries to ignore proxy settings finds no route. Every connection the agent makes is checked against rules and logged. The agent can work freely within the policy, and security is built in instead of bolted on.
Day to day it comes down to four commands. run picks the outbound path and starts the agent. trace prints every connection the agent made. guard enforces a policy and blocks what’s outside it. learn drafts a policy from what the agent actually did.
The learn command is the agile win. Nobody writes a security policy from first principles; you run the agent once doing normal work and log everything it connects to. Your security engineer or tech lead reads the log, sees that the agent pinged GitHub to read issues and DockerHub to pull images and npm to fetch packages, strikes anything obviously wrong, and locks in the rest. Under that policy, the agent works freely. A hostname that isn’t allowed is never even looked up by DNS, so DNS itself can’t be used to leak data.
For teams that want to run agents on their own machines or in their own data center, this is the security model that makes sense. The agent gets autonomy within bounds. The bounds are readable and were drafted from watching the agent work normally, so they’re tight without being brittle. Every connection is logged, so if something does go wrong, you have the evidence. Security is real, not theater.
The policy engine runs on the machine where the agent runs, so the team can iterate on policy without API calls or waiting for a security review. You see the agent tried to connect somewhere, edit the policy to allow it or block it, and test the change against old logs to see what would have happened. The feedback loop is minutes, not weeks.
There’s a second engine. Scope brings the same idea to the company VPN. It learns who actually uses which systems inside your network and drafts least-privilege rules for the gateway, so a stolen login doesn’t open the whole office. Scope is for infrastructure; VPN Works is for the team running the agents themselves.
Both tools are Alphas, tested on Linux. The live demo replays real runs of an agent trying to leak a deploy token, and you can edit the policy against the real engine, compiled to WebAssembly, to see what would have been blocked. How It Works covers the sandbox in detail.
For agile teams that want to ship faster with agents but need security that doesn’t slow them down, VPN Works solves the standoff. The agent gets autonomy. Security gets proof. The team doesn’t need permission from a gatekeeper to change the rules; they draft and test policy on their own. That’s how you run fast and safe at the same time.