Show HN: Sandboxing untrusted code using WebAssembly
Summary
This Show HN highlights Capsule, a secure runtime that runs untrusted code inside isolated WebAssembly sandboxes for AI agent tasks. It provides per-task resource controls, Python and TypeScript/JavaScript integration, an HTTP client within the sandbox, and strict file and environment access policies, plus a structured JSON task envelope for results and metadata.