Awesome to see a project deal with prompt injection. Using a WASM is clever. How does this ensure that tools adhere to capability-based permissions without breaking the sandbox?
However, this design is still under development as it creates quite a bit of challenges.
Every time a project is shared that uses WASM.