Node.js sandbox - executes untrusted JavaScript for embedded scripting
github.com
github.com
So IMHO, it's a good start but is not quite there yet, I'm not an expert in security but I don't think just because you are using V8 and a separate process model doesn't mean you will achieve the same level of sandboxing that Chromium provides. In fact, Chromium relies a lot in several security mechanism of the OS:
Windows: http://www.chromium.org/developers/design-documents/sandbox
Linux: http://code.google.com/p/chromium/wiki/LinuxSandboxing
OSX: http://www.chromium.org/developers/design-documents/sandbox/...
So if you just want to keep your globals clean, running the code in a separate V8 Context is more than enough, I did it once for a javascript library that was corrupting one of my global types(https://github.com/firebaseco/safe_datejs).
We are in a Cloud era, if you really need to run untrusted code on the server side you should be using Virtual Machines instead of a processes, or even better, create a web hook for your web app. I like the initiative but I'm having a hard time trying to find a use case for this.
This thing gives the impression that user code is pre-emptible (it really just forks the process under the hood), whereas using vm naively risks blocking your process (infinite loop in user code will gimp the server).
There's also some pseudo-console.log hack to allow communication from user code to the outside world.
Even so, I don't see the point of this either. vm + forked child process will do the same thing, it's much more versatile, and if you're working a use-case where running untrusted code is necessary, you're probably good enough with Node to cook up this kind of solution in no more than a few minutes.