Koda v29 shipped a new beta feature yesterday that lets users execute AI-generated JavaScript locally without sending data to a remote server. The entire code execution engine lives inside a single 92kb HTML file, proving that heavy backend infrastructure isn't always required for safe AI code previewing. This approach prioritizes speed and client-side security over the multi-megabyte overhead of traditional in-browser Python environments.
The Ghost Dimension Technique
The sandbox relies on the HTML sandbox attribute with a specific configuration: allow-scripts is enabled, but allow-same-origin is explicitly omitted. By leaving out same-origin permissions, the browser assigns the iframe a unique, opaque origin. This traps the AI-generated code in what the developer calls a "ghost dimension." If the code attempts to read Supabase tokens from localStorage or manipulate the parent DOM, the browser blocks the action entirely. The script can execute JavaScript, but it cannot touch the host application's real state.
Killing Infinite Loops in 3 Seconds
AI models frequently hallucinate infinite loops, which would normally freeze the user's browser tab. To prevent this, the sandbox overrides console.log to pipe output back to the UI via postMessage. More importantly, the execution is wrapped in a hard 3-second setTimeout. If the code does not finish within that window, the parent process forcefully kills the iframe. This ensures that a runaway while(true) loop from a hallucinating model doesn't crash the user's phone or desktop browser.
Why No Python Yet?
The developer intentionally excluded Python support to adhere to a strict 92kb bundle limit. Running Python in the browser typically requires Pyodide and WebAssembly, which adds over 10MB to the bundle size. Kodaโs core philosophy is to load in under one second on a 3G mobile network. Adding a 10MB Python engine would destroy that performance metric, so the current release is strictly vanilla JavaScript. The team prefers a blazing-fast JS sandbox over a bloated Python one for this beta phase.
Key Takeaways
- Omitting
allow-same-originin iframe sandboxes creates an opaque origin that blockslocalStorageand DOM access. - A hard 3-second timeout with
postMessagepiping effectively mitigates infinite loop crashes in client-side execution. - Pyodide's 10MB+ overhead is incompatible with sub-second load time goals on mobile networks, making vanilla JS the pragmatic choice for lightweight AI tools.
The Bottom Line
We need to stop assuming AI code execution requires heavy serverless functions or massive WebAssembly bundles. This 92kb solution proves that browser-native security primitives, when configured correctly, are often sufficient for safe, instant code previews.
Try Breaking It
Koda v29 is live at koda-aicodementor.netlify.app with the sandbox enabled as a beta feature. Users are invited to test the limits by asking the AI to write a Fibonacci sequence and clicking "Run," or by generating an infinite loop to see the 3-second bouncer in action. The developer is actively looking for edge cases that might allow code to escape the ghost dimension.