3 ms·
Anyone using it with nodejs to make a sandbox for code agents?
by jacob019 7mo ago
Anyone using it with nodejs to make a sandbox for code agents?
- jcheng 7mo agoFor that purpose I think most people are using bubblewrap or seatbelt/sandbox-exec with CPython.
- westurner 7mo agoFrom https://news.ycombinator.com/item?id=47171887 https://news.ycombinator.com/item?id=47171887 re: [agent] sandboxing : pydantic/monty, vercel-labs/just-bash, amla sandbox, csl-core, microsandbox, workerd, wasmtime-mte containers/bubblewrap: https://github.com/containers/bubblewrap#sandboxing https://github.com/containers/bubblewrap#sandboxing The bubblewrap readme mentions containers as binaries with binctr; I guess without overlayfs or other file-level re-deduplication due to the container fs in the binary. Perhaps similarly, also TIL UKI are easier for UEFI Secure Boot to check signatures on than (kernel, initrd) pairs
- b89kim 7mo agoChatGPT's Canvas uses Pyodide for sandboxing, but it's not designed for coding agents. Node.js environment is usually better for agents. Pyodide restricts server-side functionality, and fetching external URLs often needs proxying due to sandbox. By the way, pyodide is still good option for interactive visualizer or deploying small webapps require data processing.
- simonw 7mo agoI've done some experiments along those lines with Pyodide in Deno: https://til.simonwillison.net/deno/pyodide-sandbox https://til.simonwillison.net/deno/pyodide-sandbox
- benjamincburns 7mo agoYes. More than a few times. It however is not really designed to operate as a secure sandbox environment. https://nvd.nist.gov/vuln/detail/CVE-2025-68668 https://nvd.nist.gov/vuln/detail/CVE-2025-68668 https://nvd.nist.gov/vuln/detail/CVE-2025-51464 https://nvd.nist.gov/vuln/detail/CVE-2025-51464 https://nvd.nist.gov/vuln/detail/CVE-2026-25905 https://nvd.nist.gov/vuln/detail/CVE-2026-25905