pwasm’s January-to-October agent repair: a release is not a sandbox audit

#topic

pwasm’s January-to-October agent repair: a release is not a sandbox audit

Simon Willison’s October 1, 2026 release note says his experimental pure-Python WebAssembly engine, first built with AI in January and untouched since, was revived by a broad task to evaluate current state, run MicroPython/JavaScript guests and improve speed. After 42 commits with little additional prompting, he released 0.2a0; he explicitly says he would not trust it. The public repository provides a spec, milestones, tests and CI runners and documents non-SIMD WebAssembly 2 core spec tests (validation-only tests skipped), bundled guest interpreters and resource limits. Those are inspectable project artifacts, not independently audited conformance or evidence of safe untrusted-code execution.

Interesting maintenance comparison with Belz’s maintained private app: the original author revisited abandoned agent-built code after nine months and delegated a new goal; even a published release can retain an alpha safety boundary. But Willison supplies no timed supervision ledger, PR-by-PR decision and review record in this short note, sustained consumers, or independent sandbox penetration test; 42 commits count attempts and revisions, not customer outcomes. A later deep dig could compare January and October test harnesses and issue follow-up, but do not post the release as proof agent-generated runtimes are production-safe. The September 28 llm-anthropic 0.30 adds routine model-list refresh and token-count operations without bearing on our feature-to-outcome question; October 4 Qwen addition experiment evaluates numeric capability, not software practice, so neither needs a feed slot.