Skip to content

code_interpreter

code_interpreter

Code interpreter tool — Python execution with AST validation + hardening.

Security model (defense in depth):

  1. AST allowlist validation (this module) rejects code before it runs: imports outside a small supported set, private-attribute walks, and calls to eval/exec/compile/__import__/open/getattr &c. This replaces the old substring blocklist, which was trivially bypassed (e.g. getattr(__builtins__, 'sys'+'tem') or a simple space: eval ('...')).
  2. Isolated interpreter — the child runs with -I -B -S (isolated mode, no .pyc, no site), a sanitized environment, and POSIX resource limits (CPU + address space + no new files) applied in a preexec_fn.
  3. Outer sandbox — on a server this tool should run inside the Docker sandbox (see code_interpreter_docker / deploy/docker/Dockerfile.sandbox) or be disabled entirely. AST validation is a filter, not a jail: the Docker boundary is the real containment for untrusted code.

Classes

UnsafeCodeError

Bases: ValueError

Raised when submitted code fails AST validation.

CodeInterpreterTool

CodeInterpreterTool(timeout: int = 30, max_output: int = 10000)

Bases: BaseTool

Execute Python code after AST validation, in a hardened subprocess.

Source code in src/openjarvis/tools/code_interpreter.py
def __init__(self, timeout: int = 30, max_output: int = 10000):
    self._timeout = timeout
    self._max_output = max_output