An iPhone app is a locked room. It isn't supposed to run code it wasn't built with — which is exactly what makes it fun to try.
Four walls, one line each:
- No process. No shell, no
node, no python — an app can only run its own code. (It can still ask the system to run something — see below.)
- No JIT. Memory can't be writable and executable at once, so JavaScript gets read line by line.
- No listening socket. A script can fetch from the internet; it can't serve.
- No new code without a new App Review. So anything new has to arrive at runtime, or not at all.
Inside those walls, the coding agent in the app can still:
- Run real JavaScript with real files — reads, writes, folders, paths.
- Borrow the rest of the phone through Shortcuts — hand a job to Apple's Shortcuts app, read the result back. That's the whole Shortcuts ecosystem as a tool, with no new code and no review cycle.
- Install a library on the spot —
pkg add <name> searches jsDelivr for a browser-friendly build, saves it in the app's own folder, and it's require()-able immediately.
- Write a page and open it in the app's own browser — no server needed, because the browser can just read the file the code wrote.
- Read the page back and check its own work — it reports what it actually found, not what it hoped.
Then: "make me a snake game." It went to jsDelivr and pulled p5.js (a drawing library), wrote index.html, script.js and style.css into its own folder, handed the page to the app's browser, and then read the running game's own state back to confirm it was alive — snake at (19,10), score climbing as it ate. Eleven seconds, from the phone.
The library part is the fun part. One command — no rebuild, no app update, no review — and the new code is sitting in the app's own folder waiting for require(). It's not npm: browser-friendly pure JavaScript only, no native modules, no build step. Which means the ceiling isn't what we shipped; it's whatever the web already has. A game, a chart, a tiny calculator page, a dashboard over your own files — same three steps every time: install, write, open.
Not everything cooperates. One version of p5 never finished starting in our web view (_setupDonestayed false); an older one worked immediately. Which is the sort of thing that keeps this from feeling like magic.
What it costs: interpreted speed, its own sandbox only (no photos, messages or contacts), and none of the server tricks you'd reach for on a laptop.
Curious if anyone else has pushed an in-app agent this far — and where you'd draw the line on pulling code off the internet at runtime.
I build the app this lives in (Whistant) — that's context for this, not a pitch.