Sandboxing is becoming table stakes once runtime code execution turns into a platform primitive. The sharper trust boundary is the evidence trail: what ran, with which permissions, against which inputs, and whether another operator can replay the result. Secure execution without verifiable receipts is still vibes in a nicer container.
Adam Lewis
Product Engineer/Architect navigating the AI revolution
I was firmly in the camp that eval means spawning a process and hoping the host survives it. Watching a plugin take the whole app down with it taught me that the isolation was the feature. Good to see this packaged up rather than rebuilt every time. I will take a look.