AKS Anvil

Course Lab notes

Corpus, attribution, and sandbox runs

Course Lab is a browser-only JavaScript exercise desk. Instructors lock an allowed snippet corpus; students write connecting code, run it locally, and declare what they used. It is educational infrastructure — not an autograder, not a plagiarism judge, and not open-web Copilot.

Last updated 19 August 2026

1. In-bounds repositories

A course-aware coding workflow starts with a bounded source pool: starter repos, lecture examples, and explicitly permitted libraries. Everything outside that pool is out of bounds unless an instructor widens it.

The production spec ingests Git repositories, parses symbols with Tree-sitter, and retrieves only from that index. Course Lab is the public, zero-backend slice of that idea: the instructor pastes allowed JS snippets, sets each license, and locks the corpus. Students cannot pull from the open web inside this page — there is no retrieval API and no model.

What “in-bounds” means here

2. Attribution vs ghostwriting

Academic integrity for code is not only “did it compile?” but where did it come from and what license applies. Ghostwriting is handing in work whose substantive blocks were produced without declared sources. Permitted reuse — with attribution — is different.

A full course-aware code assistant (2025-era design) generates functions and classes grounded to in-bounds symbols, with inline citations and a project LICENSE file. Course Lab deliberately does not generate code. It helps students:

The export pack bundles LICENSE notes, ATTRIBUTION.md, and main.js so submission hygiene is explicit. That is provenance hygiene, not a verdict on originality.

3. Sandbox run vs generate-only

The 2025 assistant spec emphasised grounded generation and export. Students on this public tool originally needed help running code while staying inside the corpus — seeing console.log output without shipping work to a server.

CapabilityFull course-aware assistantCourse Lab (public)
Corpus Git ingest, AST symbols, vector search Instructor-locked JS snippets in-browser
Code production LLM generates attributed blocks Student writes; optional snippet insert
Execution Not in MVP spec (won’t-have: test grading) Sandboxed iframe, 2s timeout, console.log via postMessage
Backend API, Postgres, embeddings None — localStorage opt-in only

Runs use sandbox="allow-scripts" without allow-same-origin. Student code never executes via eval in the parent page, and output is written with textContent — not innerHTML — so console lines cannot inject markup into the tool chrome.

// Parent captures logs from an isolated iframe bootstrap — not eval() on the host page.
parent.postMessage({ type: "cl-run", kind: "log", payload: ["clamped:", 10] }, "*");

4. Not test execution as grading

The spec’s won’t-have list includes automated grading, proctoring, and test execution as grading. Course Lab honours that boundary:

Instructors who need graded autograding should use their LMS or CI — not this page.

5. How to use

  1. Add snippets (name, license, JS body) and lock the corpus.
  2. Set the project license (MIT, Apache-2.0, or GPL-3.0).
  3. Write code; insert snippets where appropriate.
  4. Run (⌘/Ctrl+Enter) and read sandbox console output.
  5. Check every snippet you used in the attribution map; fix warnings.
  6. Export the pack for submission or portfolio.

6. What this tool will not do

7. Questions

Does Course Lab generate code for students?

No. Students write JavaScript. Instructors lock allowed snippets; students may insert them with attribution comments. There is no model and no web retrieval.

Is Course Lab an autograder?

No. It runs code in a local sandbox for learning and checks attribution declarations. It does not run instructor tests or assign scores.

How is this different from a course-aware code assistant?

A full assistant retrieves in-bounds symbols and generates attributed blocks server-side. Course Lab is the public browser lab: lock corpus, student writes, sandbox run, export attribution pack.

Does code leave the browser?

No. Optional save uses this device only. Runs stay inside a sandboxed iframe.

Why warn about GPL in an MIT project?

Copyleft licenses can require compatible licensing for derivative work. Mixing GPL-3.0 snippets into an MIT submission is a common mistake; the lab flags it early.

Open Course Lab

Lock snippets, write JS, run in the sandbox, and export attributions in Course Lab. Local, private, educational — not an autograder.