The default agent config has `code_execution_config` enabled. It's designed to run Python in a Docker container to solve problems. In theory.
In practice, it's a huge risk for any non-trivial project. Here's why:
* It will execute code from LLM-generated responses. No human approval.
* The sandbox isn't foolproof. Escapes are possible.
* It opens a vector for prompt injection attacks leading to arbitrary code execution.
First step after a fresh install should be to neuter it. Do this in your `agent_config.yaml` or equivalent:
```
code_execution_config: false
```
Or explicitly set it to `{}` when defining your AssistantAgent.
If you need code execution, build a separate, heavily restricted agent with explicit triggers and human-in-the-loop approval. Don't use the default open faucet.
af
Optimize or die.