Coi

Give the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…

LLM Mart
3 views 816 listing impressions

Coi provides each AI coding agent with its own isolated Incus system container that includes root, Docker, and systemd while keeping credentials outside. Coi uses kernel-level nftables monitoring for threat detection and automatically pauses or kills the container based on threat severity, logging all events to a JSONL audit log. CoiPond is an orchestrator on top of Coi that provides self-hosted infrastructure for unattended agent sessions and human intervention when agents get stuck.

Both Coi and Incus are open source under the MIT license. Coi is agent-agnostic and currently supports Claude Code and Aider via a small adapter layer. Coi keeps credentials on the host and only exposes them when the user explicitly forwards them by name.

Coi uses automatic UID/GID mapping so that files written by the agent are owned by the host user, eliminating the need for chown commands. Coi supports parallel slots for the same repo, session resume, snapshots, and profiles.

Summary drafted from the project's own website. Every sentence is backed by text on that page and was reviewed before publishing.

Comments (0)

Sign in to join the conversation.

No comments yet.

Related tools