Urgent.News

What's breaking now, across thousands of outlets.

AI

Iam 12 .I Accidentally Built a Secure JS Sandbox While Patching a Bug. Here is How KODA Runs AI Code.

most ai wrappers just spit out a markdown block and say "good luck." if the ai hallucinates and writes a malicious script or an infinite loop, your machine takes the hit. yesterday, i was patching a truncated script error in koda v29. the file just... ended mid-sentence. while rebuilding the event listeners, i realized something: i didn't just want koda to write code. i wanted it to prove the…

Yesterday, a 12-year-old was patching a bug in Koda v29 when they accidentally created a secure JavaScript sandbox. The young coder wanted Koda to not only write code but also ensure it worked properly. The solution they stumbled upon was running entirely within a 92KB HTML file. The key to this breakthrough was the HTML sandbox attribute.

While rendering the AI's code into a hidden iframe, the crucial element missing was allow-same-origin. By not including this, the browser assigned the iframe a unique, opaque origin, effectively trapping it in a "ghost dimension." With this isolation, even if the AI hallucinated and tried to access sensitive data like Supabase tokens or manipulate the parent DOM, the browser would block it. The iframe could execute JavaScript, but it couldn't affect the real world.

However, AI often writes infinite loops, causing the browser tab to freeze. To combat this, the coder overrode console.log, directing output back to the UI via postMessage. Additionally, the execution was wrapped in a hard 3-second setTimeout. If the code didn't finish within this timeframe, the parent process would terminate the iframe, preventing frozen tabs and crashed phones.

Currently, Koda can only run JavaScript due to the 92KB rule. When users ask Koda to run Python or TypeScript, they receive a "coming soon" toast. The reason for this limitation lies in Pyodide, which adds a whopping 10MB to the bundle. Considering Koda's entire frontend—chat, authentication, streaming, UI, and the code runner—must stay under 92KB, adding a 10MB Python engine would undermine the app's core philosophy: providing an app that loads in under a second on a 3G mobile network.

As of now, Koda v29 is live with the sandbox as a beta feature. Users can visit koda-aicodementor.netlify.app to try it out. They can ask Koda to write a JavaScript Fibonacci sequence and click the "Run" button to watch it execute locally. Furthermore, users can test the 3-second bouncer by asking Koda to write an infinite loop, which the system will promptly kill.

Should anyone find a way to break out of the "ghost dimension," it's encouraged to share the discovery with the creator, who promises to patch it.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

Manslaughter sentence tossed after AI video of victim shown in court

In what's believed to be a first in U.S. courts, Pelkey's family used AI to create a video of his likeness to give him a voice.

  • Arizona Court of Appeals overturns 10-year manslaughter sentence
  • AI video of victim, Christopher Pelkey, deemed unreliable
  • First U.S. case using AI to create victim impact statement

More from Monday 5 October →