The core insight behind Codemode is an architectural split that most AI agent frameworks treat as an afterthought: the brain (harness) and the hands (execution environment) are fundamentally different trust domains, and agents need to orchestrate both without collapsing the boundary between them. Pi 1.0's Codemode gives the LLM a sandboxed JavaScript runtime—QuickJS inside WASM—that runs on the harness side, with no network, no filesystem, no timers, and limited RAM. The only escape hatch is calling more tools. The motivation is compositional. Bash composes programs that run, but some operations are native to the harness—reading images into a multimodal model's context, spawning sub-agents, invoking classifier models, generating images. These cannot be shelled out to a CLI tool without ugly workarounds involving Unix sockets and environment variables. Codemode surfaces these harness-native capabilities as JavaScript APIs the agent can call directly, while keeping the trust boundary intact. The practical consequences are significant. When an agent calls bash as a regular tool, Pi truncates output to the trailing 2,000 lines and forces the agent to manually inspect overflow files. Codemode invocations receive larger outputs structurally. The agent can express concurrency via Promise.all (Pi caps concurrent tool executions at four, queuing the rest), stash state between invocations using a store/load API on the harness side, and access internal model APIs—image generation, classification via Jev—that would otherwise waste context if exposed as regular tools. The blog post walks through real session transcripts. One example shows an agent generating images by calling Pi's internal model APIs through Codemode. Another demonstrates mass-processing 100 GitHub issues through a Jev classifier model with concurrent Promise.all calls, sorting by frustration score, and stashing results for later retrieval. A third example has the agent building a 30-step game loop to drive a tank game engine for debugging, alternating between bash calls to the game and Jev classifier calls to decide next actions. Credit for the Codemode name goes to Cloudflare, who coined the term. Pi's implementation runs it only when MCP is enabled by default, though users can toggle it on manually via settings. The design philosophy traces back to the author's earlier posts arguing that code—not custom tool definitions or MCP servers—is the right abstraction layer for agent orchestration. Codemode is the formal realization of that position: let the LLM write code that calls tools, rather than defining ever more tools for the LLM to call. The security model is worth scrutinizing. Codemode runs inside QuickJS inside WASM—a sandbox within a sandbox—but it executes on the harness host, not the execution environment. If you use a solution like Gondolin to sandbox bash execution, your tools are sandboxed, but Codemode operates at a different trust level. The intentional limitations (no network, no filesystem, no timers) are the containment strategy. Whether that containment holds under adversarial pressure from a sufficiently capable model remains an open question. What emerges is an opinionated architecture for agent orchestration: the LLM gets a constrained programming environment to compose harness-side operations, while execution-side operations stay in bash behind whatever sandbox you've chosen. It's a cleaner separation than most agent frameworks achieve, and the real-world code examples suggest models are already picking it up naturally during sessions.