Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code.
The Incident
Most AI wrappers simply output a markdown block and say "good luck." If the AI hallucinates and writes a malicious script or an infinite loop, your machine takes the hit. Yesterday, I was patching a truncated script error in koda v29. The file just... ended mid-sentence. While rebuilding the event listeners, I realized something: I didn't just want Koda to write code. I wanted it to prove the code works. So I accidentally built a local code execution sandbox - and it's running entirely in a single 92kb HTML file.
The Ghost Dimension Technique
The trick is the <iframe sandbox="allow-scripts"> attribute. Notice what is missing?
allow-same-origin
. By omitting that, the browser assigns the iframe a completely unique, opaque origin. It is trapped in a "ghost dimension." If the AI hallucinates and tries to read my Supabase tokens from localStorage, or tries to manipulate the parent DOM, the browser just blocks it. It can execute JavaScript, but it cannot touch the real world.
To prevent infinite loops from freezing the user's browser tab, I overrode console.log to pipe output back to the UI via postMessage, and wrapped the execution in a hard 3-second setTimeout. If the code does not finish in 3 seconds, the parent process kills the iframe. This means no frozen tabs and no crashed phones.
Why JavaScript Only?
Right now, if you ask Koda to run Python or TypeScript, it just shows a "coming soon" toast. People asked why I didn't just add Python support immediately. The answer is Pyodide. Running Python in the browser requires WebAssembly, and Pyodide adds 10mb+ to your bundle. Koda's entire frontend - chat, auth, streaming, UI, and now a code runner - is 92 kilobytes. Adding a 10mb Python engine would destroy the core philosophy: an app that loads in under 1 second on a 3g mobile network. For this test release, we are strict vanilla JS. I'd rather have a blazing fast JS sandbox than a bloated Python one.
Try It Yourself
Koda v29 is live with the sandbox as a beta feature. Go to koda-aicodementor.netlify.app. Ask it to write a JavaScript Fibonacci sequence, click the "Run" button, and watch it execute locally. Then, ask it to write an infinite loop and watch the 3-second bouncer kill it. If you find a way to break out of the ghost dimension, tell me - I'll patch it.
Comments
No comments yet. Start the discussion.