I'm using the web security principle to treat this untrustworthy client(LLM) and provide it with the ability every http client can do, so that LLM can write any web app natively without any agentic UI or predefined components, in a safe, physical isolated way.