plimsoll
Documentation
A sandbox service for running untrusted, agent-authored code that reports the isolation boundary each run executed behind, and refuses the run when it is weaker than the caller demanded.
- Interactive lessons — the execution model, architecture, providers, the API broker and integration, as plain HTML pages with no build step and no network calls.
- Use it from an agent framework: a page each for Vercel AI SDK, Google ADK, Agno, CrewAI, Trigger.dev, and Mastra, each replaying recorded calls from the framework's tool to a sandbox and back.
- The physics oracle — one real run, not a lesson: an agent-written controller sent as the only file of a sandbox run, run against a cart-pole plant compiled to WebAssembly and identified by the fingerprint of its trajectory.
- A controller in C: the swing-up controller written in C, compiled to WebAssembly inside the run, run against its plant by the generic trial runner, and compared tick by tick with the same law in JavaScript.
- A power supply controller in C: a buck converter's control law in C, compiled and run the same way, whose trajectory is its JavaScript version's byte for byte in every scenario.
- Same run, different sandboxes: the oracle's run on a local container, E2B and Docker Cloud Sandboxes, with one fingerprint on every provider.
- Simulation replay pages: all eight plants in the sim image, from a delayed shower to a black hole orbit, each with a failing and a passing controller replayed.
- README on GitHub — what this is, the isolation tiers, and how to run it.
- SECURITY.md — the threat model, what "verified" means for each tier, and how to report a vulnerability privately.
Pre-1.0, single author, no external users yet, and no third-party security audit has ever been performed. The README says so at greater length.