Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code.

most ai wrappers just spit out a markdown block and say "good luck." if the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit. yesterday, i was patching a truncated script

most ai wrappers just spit out a markdown block and say "good luck."

if the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit.

yesterday, i was patching a truncated script error in koda v29. the file just... ended mid-sentence. while rebuilding the event listeners, i realized something: i didn't just want koda to write code. i wanted it to prove the code works.

so i accidentally built a local code execution sandbox.
and it’s running entirely in a single 92kb html file.

the "ghost dimension" iframe

the trick is the html sandbox attribute.
i render the ai’s code into a hidden <iframe sandbox="allow-scripts">.

notice what is missing? allow-same-origin.

by omitting that, the browser assigns the iframe a completely unique, opaque origin. it is trapped in a ghost dimension. if the ai hallucinates and tries to read my supabase tokens from localStorage, or tries to manipulate the parent dom, the browser just blocks it.

it can execute javascript, but it can't touch the real world.

the 3-second bouncer

ais love writing infinite loops.
while(true) { console.log("oops") }

if i just let the iframe run, it would freeze the user's browser tab.
so i overrode console.log to pipe the output back to the ui via postMessage, and wrapped the execution in a hard 3-second setTimeout.

if the code doesn't finish in 3 seconds, the parent process kills the iframe. no frozen tabs. no crashed phones.

why only javascript? (the 92kb rule)

right now, if you ask koda to run python or typescript, it just shows a "coming soon" toast.

people asked why i didn't just add python support immediately.
the answer is pyodide.

running python in the browser requires webassembly. pyodide adds 10mb+ to your bundle.
koda’s entire frontendβ€”chat, auth, streaming, ui, and now a code runnerβ€”is 92 kilobytes.

adding a 10mb python engine would destroy the core philosophy: an app that loads in under 1 second on a 3g mobile network.
so for this test release, we are strict vanilla js. i'd rather have a blazing fast js sandbox than a bloated python one.

try breaking it

koda v29 is live with the sandbox as a beta feature.
go to koda-aicodementor.netlify.app.
ask it to write a javascript fibonacci sequence. click the "Run" button. watch it execute locally.

then, ask it to write an infinite loop. watch the 3-second bouncer kill it.

if you find a way to break out of the ghost dimension, tell me. i'll patch it.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.