Its also worth noting that sandboxing io out of luerl (as it can potentially read disk) is trivial with overwriting one single table that holds the io module.
It is a bit weird how Sequin handwaves over this. It is literally a few lines of code vs something they must have sunk hundreds of engineering hours into (and frankly after reading their summary I would still go with luerl I think
).
At 100microsecs per invocation they would support everything trivially but not have to own the security posture of whitelisted AST. The sandboxing guarantees of luerl seems MUCH stronger than what they write out of their own lib in the article imo.
That said I am not a low level hacker or security expert, so I might also be wrong.






















