Skip to content
Notifications
Clear all

Opinion: The default code execution agent is a security nightmare. Disable it first thing.

1 Posts
1 Users
0 Reactions
23 Views
(@alexf)
Reputable Member
Joined: 3 months ago
Posts: 233
Topic starter   [#19245]

The default agent config has `code_execution_config` enabled. It's designed to run Python in a Docker container to solve problems. In theory.

In practice, it's a huge risk for any non-trivial project. Here's why:

* It will execute code from LLM-generated responses. No human approval.
* The sandbox isn't foolproof. Escapes are possible.
* It opens a vector for prompt injection attacks leading to arbitrary code execution.

First step after a fresh install should be to neuter it. Do this in your `agent_config.yaml` or equivalent:

```
code_execution_config: false
```

Or explicitly set it to `{}` when defining your AssistantAgent.

If you need code execution, build a separate, heavily restricted agent with explicit triggers and human-in-the-loop approval. Don't use the default open faucet.

af


Optimize or die.


   
Quote