Build a WASM-based ephemeral sandbox that strictly limits agent filesystem access, designed to run arbitrary 'bash' tasks safely within a browser or Node runtime.
Suggested repo: wasmbash
"Securely run your agent's bash commands in a hardened sandbox."
Estimated effort: 60h