· via Hacker News – Front Page (native)
Pi's Codemode: sandboxed JavaScript in the agent harness to orchestrate tools without context bloat
A front-page Hacker News post from the Pi team explains Codemode, a sandboxed JavaScript runtime inside the agent harness that lets models orchestrate tool calls, run workflows in parallel and keep bulky outputs out of context.

A reversal framed as a synthesis
A widely shared post published on October 6 on the lucumr.pocoo.org blog, which reached Hacker News's front page, revisits an argument its author made more than a year earlier: that agents perform better when they write plain scripts rather than loading custom tools or MCP servers into their context, including an earlier piece titled Code Is All You Need. Pi 1.0, the agent harness the author works on, now ships MCP support — but through a feature called Codemode that makes code, not ever-more tool definitions, the way a model composes its work.
The case against piling up tools
According to the post, the tool definitions a harness supplies become token structures on the model side, and whether a model reaches for them at all is a product of reinforcement learning. That is why the team leans on the CLI and bash: shells compose easily, and models already understand the file system from training, so once a shell command writes a file, the model knows it exists.
But bash has a ceiling: it can only compose programs that run. Some capabilities are native to the LLM itself. A multimodal model cannot read an image with cat, because the harness has to inject the actual image payload into the model's protocol. Spawning and coordinating sub-agents likewise depends on harness-provided tools, and having code in the execution environment talk back to the orchestrator is described as crude.
The dividing line between brain and hands
The post splits an agent setup into two systems: the harness — the trusted brain — and the execution environment where bash and tools actually run. They may share a machine, but they have separate file systems and different trust levels. The author notes that a sandboxing setup such as Gondolin constrains the bash side while the harness itself remains unsandboxed.
What Codemode actually is
Codemode is the bridge: a way for the model to express and orchestrate operations on the harness side. It runs JavaScript inside the harness, in QuickJS on a WASM runtime, under deliberate restrictions — no network, no file system, no timers, limited memory. The only thing a Codemode script can do is call more tools. Cloudflare is credited with the name, and the author notes the approach is not tied to JavaScript; Scheme or another language could serve.
The payoff is context economy. A regular bash tool call in Pi drops only the trailing 2,000 lines of output into the model's context, with the rest written to an overflow file. The same call issued from Codemode hands larger output to the script structurally, so the script can digest it and pass on only what matters.
Because it is real code, Codemode also gives agents concurrency and basic workflows. A pattern the author observes: the agent samples a handful of items from a tool response to learn its shape, then writes a script that processes the next batch. Scripts can also stash state in the transcript for later calls in the same session — held on the harness host, not in the sandbox.
Harness-side models without context bloat
Codemode also opens up APIs that make no sense as ordinary tools. Image generation and one-shot classifiers are exposed to scripts but not as regular tools, because pushing their payloads through context would waste it. The post shows snippets from real Pi sessions — the author stresses that none of the code is human-written — including an image-generation call and a script that pulls 100 open GitHub issues and runs a classifier named Jev over them for a quick sentiment analysis.
In Pi, Codemode is on by default only when MCP is enabled; otherwise it can be activated with the "defaultTools": ["+codemode"] setting.
Why it matters
The post reads as a design manifesto for agent tooling. Rather than multiplying bespoke tool definitions — the default trajectory of the MCP ecosystem — it argues for a small, generic surface (a shell plus a tightly sandboxed scripting runtime) backed by programmatic APIs. Context remains the scarce resource, and code acts as the compression layer that keeps bulky data out of it. The hard sandbox also sketches an answer to the obvious danger of running model-written code in the trusted half of the system. For anyone building agent harnesses or MCP servers, the practical takeaway is blunt: expose capabilities your agent can call from code, and resist minting a new tool for every task.
- #ai-agents
- #mcp
- #javascript
- #developer-tools
- #sandboxing