Running untrusted AI-generated code safely is the obvious hard problem.

But sometimes the problems that break an agent workflow look like boring infrastructure work.

v0.6 began as plumbing:

Persistent sandbox registry

Automatic cleanup with TTL