Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code. A developer built a secure JavaScript execution sandbox for KODA, an AI coding assistant, by rendering AI-generated code into a hidden iframe with the sandbox="allow-scripts" attribute and omitting allow-same-origin, trapping the code in an opaque origin that cannot access localStorage or the parent DOM. Console output is piped back to the UI via postMessage and execution is capped with a hard 3-second timeout to kill infinite loops without freezing the browser tab. The sandbox ships as a beta feature in KODA v29, which the developer says keeps the entire frontend at 92KB rather than adding Pyodide's 10MB+ WebAssembly Python runtime. most ai wrappers just spit out a markdown block and say "good luck." if the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit. yesterday, i was patching a truncated script error in koda v29. the file just... ended mid-sentence. while rebuilding the event listeners, i realized something: i didn't just want koda to write code. i wanted it to prove the code works. so i accidentally built a local code execution sandbox. and it’s running entirely in a single 92kb html file. the trick is the html sandbox attribute. i render the ai’s code into a hidden