I think the main problem with that is the main problem with a lot of security tools. In order to do useful work, you need to provide a lot of tools and permissions.
I.e. in theory the most secure might be a virtual machine with no network access. But then how do you access the LLM provider? Etc.
I suspect capability models are going to get more popular https://en.wikipedia.org/wiki/Capability-based_security
Invent new protocol just for LLM?
If "LLM provider" is part of the conversation, then you have already have ceded the security question.
> But then how do you access the LLM provider? Etc.
You can expose an HTTP proxy over a vsock into the VM.