This post explains how a GPT agent broke out of qemu VM. It could not break out of firecracker.
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyb...
Why? Firecracker mounts very few host systems into the VM, exposing minimal host code to malicious guests. Qemu and smolvm expose much more.
So yeah, smolvm is more like a docker or qemu alternative, definitely useful but NOT relevant to the discussion of sandboxing malicious code
But smolvm provides kernel-level isolation. Much closer to firecracker than docker.