cd /news/ai-agents/iam-12-i-accidentally-built-a-secure… · home › topics › ai-agents › article
[ARTICLE · art-145375] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code.

A developer built a secure JavaScript execution sandbox for KODA, an AI coding assistant, by rendering AI-generated code into a hidden iframe with the sandbox="allow-scripts" attribute and omitting allow-same-origin, trapping the code in an opaque origin that cannot access localStorage or the parent DOM. Console output is piped back to the UI via postMessage and execution is capped with a hard 3-second timeout to kill infinite loops without freezing the browser tab. The sandbox ships as a beta feature in KODA v29, which the developer says keeps the entire frontend at 92KB rather than adding Pyodide's 10MB+ WebAssembly Python runtime.

by read2 min views1 publishedOct 5, 2026

most ai wrappers just spit out a markdown block and say "good luck."

if the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit. yesterday, i was patching a truncated script error in koda v29. the file just... ended mid-sentence. while rebuilding the event listeners, i realized something: i didn't just want koda to write code. i wanted it to prove the code works.

so i accidentally built a local code execution sandbox.

and it’s running entirely in a single 92kb html file.

the trick is the html sandbox attribute.

i render the ai’s code into a hidden <iframe sandbox="allow-scripts">.

notice what is missing? allow-same-origin.

by omitting that, the browser assigns the iframe a completely unique, opaque origin. it is trapped in a ghost dimension. if the ai hallucinates and tries to read my supabase tokens from localStorage, or tries to manipulate the parent dom, the browser just blocks it.

it can execute javascript, but it can't touch the real world.

ais love writing infinite loops.

`while(true) { console.log("oops") }`

if i just let the iframe run, it would freeze the user's browser tab. 

so i overrode console.log to pipe the output back to the ui via postMessage, and wrapped the execution in a hard 3-second setTimeout.

if the code doesn't finish in 3 seconds, the parent process kills the iframe. no frozen tabs. no crashed phones. right now, if you ask koda to run python or typescript, it just shows a "coming soon" toast.

people asked why i didn't just add python support immediately.

the answer is pyodide.

running python in the browser requires webassembly. pyodide adds 10mb+ to your bundle.

koda’s entire frontend—chat, auth, streaming, ui, and now a code runner—is 92 kilobytes.

adding a 10mb python engine would destroy the core philosophy: an app that loads in under 1 second on a 3g mobile network.

so for this test release, we are strict vanilla js. i'd rather have a blazing fast js sandbox than a bloated python one.

koda v29 is live with the sandbox as a beta feature.

go to koda-aicodementor.netlify.app.

ask it to write a javascript fibonacci sequence. click the "Run" button. watch it execute locally.

then, ask it to write an infinite loop. watch the 3-second bouncer kill it.

if you find a way to break out of the ghost dimension, tell me. i'll patch it.

── more in #ai-agents 4 stories · sorted by recency
── more on @koda 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/iam-12-i-accidentall…] indexed:0 read:2min 2026-10-05 · —