Is the VM layer mostly for host hygiene, or are you also treating the instances as a real security boundary when something untrusted (deps or agent-written code) runs inside?