code_interpreter
code_interpreter
¶
Code interpreter tool — Python execution with AST validation + hardening.
Security model (defense in depth):
- AST allowlist validation (this module) rejects code before it runs:
imports outside a small supported set, private-attribute walks, and calls to
eval/exec/compile/__import__/open/getattr&c. This replaces the old substring blocklist, which was trivially bypassed (e.g.getattr(__builtins__, 'sys'+'tem')or a simple space:eval ('...')). - Isolated interpreter — the child runs with
-I -B -S(isolated mode, no.pyc, nosite), a sanitized environment, and POSIX resource limits (CPU + address space + no new files) applied in apreexec_fn. - Outer sandbox — on a server this tool should run inside the Docker
sandbox (see
code_interpreter_docker/deploy/docker/Dockerfile.sandbox) or be disabled entirely. AST validation is a filter, not a jail: the Docker boundary is the real containment for untrusted code.