It's meant to be a different/more secure approach compare to what Claude's doing with their sandboxing runtime: https://code.claude.com/docs/en/sandboxing. Instead of relying on linux + Mac's technology for containerization, this project spins up a completely virtual environment on a separated kernel for better security.