mitsuhiko warns AST interpreters alone are not enough to sandbox agent code
On October 10, well-known developer mitsuhiko (author of essays like "Abandoning Docker") laid out his concerns about code sandbox isolation while discussing codemode implementations (having agents generate and execute code) with other users: he is not comfortable relying on an AST interpreter as the sole isolation mechanism for code execution, given the heavy implementation effort and how tricky sandboxing is—he even has reservations about isolation based purely on wasm/workers.
Confirmed
- mitsuhiko explained that he initially rejected a shared-process codemode approach (without QuickJS) due to its complexity and lack of proper isolation; he considers such routes reasonable but wouldn't feel comfortable using them himself.
- He noted that doing only basic isolation and letting multiple calls share the same worker leads to security issues, with a live example demonstrating it.
- In the same thread, he added that opencode's trade-off of using an AST interpreter for code execution is acceptable, but if he were building Pi from scratch today, he would not start with that route.
- Developer thdxr explained that his team deliberately avoided QuickJS in their codemode implementation: it introduces wasm complexity, forces worker threads, and requires serializing data back and forth between the main thread and workers; he suggested that anyone implementing similar functionality look to their approach.
Why it matters
- As agents generating and executing code becomes a mainstream pattern, whether sandbox isolation is reliable directly determines the security boundary; mitsuhiko's stance represents the cautious camp: no single isolation mechanism (AST interpreters, shared workers, or even wasm/workers) should be trusted absolutely, and implementers must make explicit trade-offs between complexity and isolation strength.
2026-10-10 ~ 2026-10-10 · 8 related posts
Primary sources
- mitsuhiko: an AST interpreter alone is too fragile as an agent code-execution sandbox — mitsuhiko ·
- mitsuhiko: template engines like jinja2 are unsafe for untrusted input without OS-level isolation — mitsuhiko ·
- Why this team skipped QuickJS for codemode: wasm complexity, worker threads, serialization — cravenceiling ·
- [source] Why this team skipped QuickJS for codemode: wasm complexity, worker threads, serialization — cravenceiling · 2026-10-10
- [source] mitsuhiko: an AST interpreter alone is too fragile as an agent code-execution sandbox — mitsuhiko · 2026-10-10
- mitsuhiko: opencode's isolation tradeoff is fine, but he wouldn't start there with Pi — mitsuhiko · 2026-10-10
- mitsuhiko on codemode: reasonable approach, but poor isolation kept him away — mitsuhiko · 2026-10-10
- mitsuhiko: sharing a worker without OS-level isolation is unsafe for agent codemode — mitsuhiko · 2026-10-10
- [source] mitsuhiko: template engines like jinja2 are unsafe for untrusted input without OS-level isolation — mitsuhiko · 2026-10-10
- mitsuhiko demos why sharing one worker for AI agent code execution ends in OOM kills — mitsuhiko · 2026-10-10
1 near-duplicate retellings: mitsuhiko