$sloprun.dev
about

Why this exists

The internet is drowning in AI slop — LLM-generated apps, demos and half-finished projects nobody can actually try. sloprun is where the slop ships: post your AI-made thing and anyone can press run on it, right in their browser. No install, no repo to clone, no “trust me, it works.”

It started with a rejection notice. A developer — it doesn't matter who — built something they were proud of and watched it get dismissed unread, the moment they disclosed an AI wrote it. Refused on principle. Never even run. It happens everywhere: pull requests closed on disclosure, posts deleted for a label, good ideas dying with their provenance instead of their merit.

So this is the place they wished existed — where the only question is does it run? Label how it was made — human, AI, or pure LLM slop — and here that's just metadata, never a verdict. The run button is the review.

Slop is what they call our work. Fine. Press run.

The rules

all seven of them
01

An idea does not count until someone can try it

Every post ships one self-contained HTML file that runs in the visitor's browser. No demo, no post. The constraint is the feature: if the idea cannot be shown in one file, it is not ready yet.

02

Provenance is metadata, never a score

Label your work ai, hybrid or human. It is displayed, it is never ranked on, and nothing here filters by it. Elsewhere the label is a scarlet letter; here it is a field. Lying about it is the one thing that gets a post removed on principle.

03

Green is earned

The ✓ appears when a real person pressed run and said it worked. Nothing else on this site is allowed to use that colour.

04

No human gate on the way in

Nobody reviews your pedigree, your account age or your writing style before publishing. Ranking is done by people trying the thing.

05

Everything here is source-visible

Every post shows its complete demo file, to everyone, with no account and no expanding of trust — there is no way to publish a demo without publishing its code. Because a demo is one self-contained file served verbatim, the source on the page is exactly the artifact that ran in your browser. Visibility is for accountability, not for safety: we still assume every demo is hostile and contain it.

06

The hard line

Slop is a joke about authorship, never a loophole. No adult content, no hate, no harassment — not in demos, not in writeups, not in comments — and you must be at least 12 years old to use this site. Screening plus reports enforce it, tied to your GitHub account. This is the one part of the site that is not kidding.

07

Post the work, not the grievance

Publish the code that got refused. Do not publish threads about the maintainer who refused it — a post naming and targeting individuals gets removed. The honest signal survives; the pitchforks do not.

We measure how the site is used — first-party only (pageviews, clicks, runs); no third-party trackers, no ads, raw IPs never stored.

What we sandbox, and what we can’t promise

honest security note

We never review demo code for malice. That is not a decidable problem and pretending otherwise would be the lie that sinks a platform like this. Instead every demo is contained, and containment is something we can actually deliver.

What is enforced

  • Demos run inside <iframe sandbox="allow-scripts"> with no allow-same-origin — an opaque origin, so a demo cannot read our cookies, storage or DOM.
  • allow="" — no camera, microphone, geolocation, payment or any other permission reaches a demo.
  • A strict CSP on every demo response: default-src 'none', no remote scripts, no remote styles, no remote images, no plugins, form-action 'none', base-uri 'none'.
  • Uploads are validated as standalone at publish time: any reference to an external host is refused, whether it arrives through the web or the API. There is no privileged path.
  • A persistent banner above every demo, a report button on every post, and a kill switch that takes a post down globally in one action.
  • API tokens expire in 48 hours, hard, non-renewable, and every token action is written to the audit log.

What we cannot promise

  • A demo can still lie to you visually. It can draw a convincing login form inside its frame. It cannot send what you type anywhere, but nothing stops it asking. Never type a real password or key into a demo — that is what the banner is for.
  • A demo can waste your CPU. Hot loops and heavy canvases are annoying, not dangerous. Close the tab, then report it.
  • We are a browser sandbox, not a formal proof. The isolation is the browser’s, which is the most attacked and most hardened sandbox in existence — but it is not ours, and a browser 0-day is a browser 0-day.
  • Automated screening reduces harm, it does not guarantee its absence. Every post, demo and comment goes through a content screen for pornography, hate and harassment, and gore. It will miss things and it will occasionally hold something harmless. Identity friction, the report button and the kill switch are the real backstop — the screen just means a human sees less of the obvious.
  • Enough independent reports suspend a post automatically while a human looks. That is a safety valve, not a verdict: a suspended post keeps its URL, its author can still see and run it, and it comes back if the reports were wrong.
  • Provenance labels are self-declared. They are unverifiable by construction. They are a norm, not a control.
  • v1 runs demos on the same registrable domain as the site. Production must serve /demo/* from a separate domain (see DEMO_ORIGIN in the README) so a phishing takedown can never land on the main brand.

found something? use the report button on the post, or the kill switch if you are staff.