Skip to main content

code-runner

Execute Python code snippets with best-effort resource limits. Supports data analysis, visualization, and quick scripts.

Informations de source

Dépôt
fuyuxiang/echo-agent
Dernière activité de la source
1 octobre 2026 à 03:25
Langue détectée de SKILL.md
anglais
Étoiles
1 055
Forks
27

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.

Explorateur de fichiers
2 fichiers

Affichage de SKILL.md

SKILL.md
Instructions source · Aperçu en lecture seule
name
code-runner
description
Execute Python code snippets with best-effort resource limits. Supports data analysis, visualization, and quick scripts.
version
1.0.0
metadata
{"echo":{"tags":["Python","Code","Execute","Sandbox","DataAnalysis"]}}
# Code Runner Python code execution with resource limits and import restrictions; this is not an isolation boundary. ## Usage ```bash python3 scripts/safe_exec.py "print(sum(range(100)))" python3 scripts/safe_exec.py --file script.py python3 scripts/safe_exec.py --timeout 10 "import time; time.sleep(5); print('done')" ``` ## Security Best-effort guards (NOT a true sandbox — code can still read the filesystem): - **Timeout**: default 30 seconds, configurable - **Memory limit**: 256MB on Linux (via resource.setrlimit); not enforced on macOS - **Blocked patterns**: `os.system`, `subprocess`, `shutil.rmtree`, `__import__('os')` - **AST check**: scans code for dangerous import patterns before execution - **Isolated working dir**: runs in a fresh tmpdir, cleaned up after execution - **Minimal env**: only PATH/HOME/LANG passed to subprocess **Limitations**: This is NOT a security sandbox. The child process can read arbitrary files on the host filesystem. For untrusted code, use a container-based executor (e.g., docker-manage skill) instead. ## Allowed Libraries Safe for use (common data/analysis): - `math`, `statistics`, `decimal`, `fractions` - `json`, `csv`, `re`, `datetime`, `collections` - `pandas`, `numpy` (if installed) - `matplotlib` (saves to file, no display) ## Blocked Patterns ```python BLOCKED = [ "os.system", "os.exec", "os.popen", "os.remove", "subprocess", "shutil.rmtree", "importlib", "__import__", "eval(", "exec(", "open('/etc", "open('/root", ] ``` ## Example Workflows Data analysis: ```python import pandas as pd df = pd.read_csv("/tmp/data.csv") print(df.describe()) print(df.groupby("category")["amount"].sum()) ``` Quick plot (saved to file): ```python import matplotlib.pyplot as plt plt.plot([1,2,3,4], [1,4,2,3]) plt.savefig("/tmp/plot.png") print("Plot saved to /tmp/plot.png") ```
Voir sur GitHub