Lesson 14 / 25

Code Execution Tools

Let an agent run code for exact computation, inside a sandbox.

Let code do the arithmetic

Models can make slips in arithmetic, date maths and data wrangling. A code-execution tool lets the agent write a small script, run it and read the output, so numbers come from computation rather than recall. Because the code is model-written, run it in a sandbox: no access to your secrets, limited files, no unrestricted network, and a time limit.

A limited runner

This sketch uses a subprocess with a timeout. A subprocess alone is NOT a real sandbox; production systems use containers or dedicated sandboxes with no secrets mounted.

import subprocess, sys

def run_python(code: str, timeout_s: int = 5) -> str:
    try:
        p = subprocess.run([sys.executable, "-c", code],
                           capture_output=True, text=True, timeout=timeout_s)
    except subprocess.TimeoutExpired:
        return "Error: timed out"
    return (p.stdout + p.stderr)[:2000]      # clip the output

Quick check: Why run model-written code in a sandbox?

  • Python requires it
  • Sandboxes make code faster
  • The code is always correct
  • To limit the damage of mistakes or malicious code
Answer

To limit the damage of mistakes or malicious code — Isolation contains whatever the generated code does, intended or not.