Yup, very irresponsible. And then the horror stories.
yoloai new --network-isolated ...
ONLY agent API traffic allowed. Everything else gets blocked by iptables. yoloai new --network-allow api.example.com --network-allow cdn.example.org ...
ONLY agent API traffic + api.example.com and cdn.example.org. Everything else blocked by iptables.