mitsuhiko demos why sharing one worker for AI agent code execution ends in OOM kills

mitsuhiko · x · 2026-10-10

Developer mitsuhiko responded to whether running AI agent-generated code in a separate worker is enough: with only basic isolation and a shared worker, an infinite loop exhausts memory and kills the worker.

He adds that switching to QuickJS doesn't help either — the problem is the infinite loop itself, not the isolation boundary. A concrete look at the trade-offs in sandboxing code execution for agents.

Related event: mitsuhiko warns AST interpreters alone are not enough to sandbox agent code(8 posts)→

Original post →

More from coding & agent

coding & agent channel →