Kenton Varda argues that personal AI code generation does not fit the usual cloud model of one centrally hosted application shared by all users. His Gadgets prototype treats each document-like item as its own app with separate code and data. A user can instantiate a shared blueprint, modify that instance with an agent and share the result through platform-managed permissions.
The demo includes simple tools for slides, email filtering and pull-request review. Varda shows an agent changing the slide editor itself to satisfy a presentation request. He says the client runs in a null-origin iframe with a restrictive content security policy, while server-side code runs in a dynamic Workers sandbox backed by Durable Objects; communication crosses a controlled messaging and RPC path.
The live prompt attempt fails because of internet access, and Varda says Gadgets was not being open-sourced at the talk despite an earlier plan. His sweeping assurance that bugs cannot matter should be read as a claim about the intended isolation boundary, not proof of absolute security. The general lesson is to give generated code only the capabilities needed for one shareable task.
Watch on YouTube




