All news
devtoolsproductcybersecurityai

Clawk: Coding Agents Run in Disposable VMs, Not Laptops

14 Jul 2026

What's new

A new devtool called clawk is tackling a problem that's becoming increasingly relevant as AI coding agents get more autonomy: what happens when an agent runs directly on your laptop? Clawk's answer is to give each coding agent its own disposable Linux VM instead of letting it touch the host machine.

The tool works with Claude Code, Codex, and shell agents, positioning it as a general-purpose isolation layer rather than a single-vendor integration.

How it works

Rather than running agents against your local filesystem and network, clawk spins up isolated VMs per agent session. Key details from the release:

  • Installation is via Homebrew (brew install clawkwork/tap/clawk), or from source with Go 1.26+.
  • Primary support targets macOS 14+ on Apple silicon.
  • Linux support exists via Firecracker but is labeled experimental.
  • Clawk supports multi-repo ticket workflows, using git worktrees and coordinated pull requests through clawk work and clawk pr commands — useful for teams managing agents across multiple repositories.
  • Security-oriented design choices include allow-listed outbound traffic from VMs and ssh-agent forwarding, so agents can git push without SSH keys ever entering the VM.
  • Idle VMs automatically release memory and suspend to disk, presumably to manage resource overhead when agents aren't active.

The project is pre-1.0 and explicitly described as moving fast, with breaking changes expected between releases.

What's missing

The report notes several open questions: there's no pricing or licensing information, no disclosed team size or funding behind the project, and no performance benchmarks comparing clawk to other sandboxing or VM approaches for coding agents. Usage or adoption numbers aren't available either, and it's unclear exactly how the experimental Firecracker-based Linux support differs functionally from the macOS-first path.

Why founders should care

For founders building with or around AI coding agents, clawk's approach signals a few likely trends worth tracking:

  • As agents gain more autonomy — writing code, pushing to git, making network calls — the perceived risk of running them directly on developer or production machines likely increases. Tools like clawk suggest that isolation-first architectures may become a more standard expectation for agent tooling, not just a nice-to-have.
  • Support for multiple agent frameworks (Claude Code, Codex, shell agents) hints that founders building agent-adjacent tools may benefit from designing for interoperability rather than betting on a single agent ecosystem.
  • The emphasis on security features — allow-listed traffic, key isolation, automatic VM suspension — suggests that operational risk reduction is likely becoming a selling point for teams evaluating whether to adopt agentic coding tools at scale.
  • The experimental state of Linux support is a reminder that even promising devtools often ship with uneven platform coverage early on, which could affect adoption timelines for teams outside the macOS/Apple silicon default.

Risks to watch

A few caveats are worth flagging for anyone considering early adoption:

  • Pre-1.0 instability: breaking changes between releases could disrupt workflows for teams that integrate clawk early.
  • Linux reliability: since Linux support via Firecracker is experimental, teams outside macOS on Apple silicon may encounter rougher edges.
  • Installation constraints: reliance on Homebrew and specific Go/macOS version requirements could limit installation flexibility for some environments.

Bottom line

Clawk's disposable-VM model for coding agents reflects a broader shift toward isolating AI agents from host environments as their capabilities — and the risks that come with them — expand. With no pricing, benchmarks, or adoption data yet public, it's early days, but the underlying design choices offer a useful signal for founders thinking about how to safely integrate autonomous coding agents into their own workflows.

Sources