Sandboxing untrusted code using WebAssembly
Details
- External ID
- 46871387
- Source
- HN
- Company
- —
- Product
- Sandboxing untrusted code using WebAssembly
- Website domain
- github.com
- Launched
- Feb. 3, 2026
- Cohort
- —
- Upvotes
- 76
- Upvotes percentile
- 0.8638814016172507
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi everyone,I built a runtime to isolate untrusted code using wasm sandboxes.Basically, it protects your host system from problems that untrusted code can cause. We’ve had a great discussion about sandboxing in Python lately that elaborates a bit more on the problem [1]. In TypeScript, wasm integration is even more natural thanks to the close proximity between both ecosystems.The core is built in Rust. On top of that, I use WASI 0.2 via wasmtime and the component model, along with custom SDKs that keep things as idiomatic as possible.For example, in Python we have a simple decorator: from capsule import task @task( name="analyze_data", compute="MEDIUM", ram="512mb", allowed_files=["./authorized-folder/"], timeout="30s", max_retries=1 ) def analyze_data(dataset: list) -> dict: """Process data in an isolated, resource-controlled environment.""" # Your code runs safely in a Wasm sandbox return {"processed": len(dataset), "status": "complete"} And in TypeScript we have a wrapper: import { task } from "@capsule-run/sdk" export const analyze = task({ name: "analyzeData", compute: "MEDIUM", ram: "512mb", allowedFiles: ["./authorized-folder/"], timeout: 30000, maxRetries: 1 }, (dataset: number[]) => { return {processed: dataset.length, status: "complete"} }); You can set CPU (with compute), memory, filesystem access, and retries to keep precise control over your tasks.It's still quite early, but I'd love feedback. I’ll be around to answer questions.GitHub: https://github.com/mavdol/capsule[1] https://news.ycombinator.com/item?id=46500510
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- sandboxing code with webassembly
- Manually corrected
- False
Could you build this?
Partial Writing a wrapper around an existing Wasm engine is straightforward, but creating a secure sandbox that isolates untrusted code requires rigorous security boundary engineering and low-level runtime integration.
What it would actually take: This requires embedding a WebAssembly runtime (such as Wasmtime, Wasmer, or V8) into a host language (TypeScript/Node.js or Rust) and defining strict WASI capabilities, memory limits, CPU cycle fuel metering, and secure hostcall bindings. The primary difficulty is hardening the sandbox against side-channel attacks, escape vulnerabilities, and CPU/memory exhaustion while ensuring near-native performance for dynamic untrusted scripts. It requires systems programmers with deep expertise in WASI specifications and runtime isolation security.
Discussion
20 comments analyzed.
Competitors mentioned: just-bash (for coding agent execution), Modal (for remote infrastructure decorator pattern), Pyodide (for Python in WebAssembly with C extensions), Mruby (for sandboxed VM with limited functionality)
Concerns raised: Unclear how duck-typed languages like Python work with WASM component model IDL, Decorator syntax confusing without clear understanding of what runs where, No network limits to prevent resource exhaustion loops or massive downloads, WASI tooling maturity and dynamic linking not yet at Emscripten/Pyodide level, Unclear whether agents run fully in sandbox or if code is extracted and run dynamically
Feature requests: More complete examples showing AI agent integration patterns, Network request limits and rate limiting controls, Option to run sandbox code as separate file for transparency, Visual/debugging tools to see which code runs directly vs. in sandbox, Support for Python libraries like Pandas in WebAssembly
Competitors
Other products that read as similar to this one — 179 launches clear the similarity bar, closest 8 shown.
Attention rank: #29 of 180 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 94 days after the earliest competitor.
- NetWasm · hn · 2026-09-29 · 5 upvotes · similarity 0.56
- sandbin · ph · 2026-09-12 · 2 upvotes · similarity 0.52
- Codex CLI compiled to WASM running in the browser · hn · 2026-08-19 · 5 upvotes · similarity 0.51
- Zerobox · hn · 2026-03-30 · 141 upvotes · similarity 0.49
- Secure Core FFI · ph · 2026-09-14 · 1 upvotes · similarity 0.48
- Talos · hn · 2026-06-18 · 106 upvotes · similarity 0.46
- Firefox in WebAssembly · hn · 2026-07-15 · 273 upvotes · similarity 0.44
- Numax · hn · 2026-06-16 · 6 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.