I'll be sure to check this out but in the meantime, I'd like to ask: Isn't it generally a good practice to run coding agents in a VM? It provides a security boundary so that the agent is restricted to the VM.

How does this compare? I see it's an "isolated sandbox", but what exactly does that mean?

Yeah when you self-host pipod, all of your pi sessions are running on your own VM. Within that VM, each pi session runs in its own container.