Skip to main content

awrepl

A REPL an agent can actually use — state that survives between turns.

pip install awrepl
from awrepl import ReplSession

session = ReplSession("agent-1")
result = session.execute("items = [1, 2, 3]")
result = session.execute("print(len(items))")
print(result.stdout)  # "3"
session.close()
awrepl run "print('hello')"
awrepl serve                    # Interactive session
awrepl --session myagent run "x = 42"
awrepl --self-test              # Verify the contract

The problem it exists for

An agent given one-shot shell commands rebuilds its whole world on every call, so it guesses instead of looks. Every variable it wanted is gone the moment the command exits. This REPL keeps state.

You ask the live object, not the agent's memory.

# Turn 1
session.execute("data = load_file('config.json')")

# Turn 2 (later, different agent instance)
session.execute("print(data['server'])")  # data is STILL there

⚠️ This is NOT a sandbox

Critical: awrepl executes arbitrary code with the privileges of the process that started it.

It does not protect against:

  • Filesystem access — code can read/write/delete files
  • Network access — code can make HTTP requests, connect to services
  • Subprocess execution — code can launch processes and scripts
  • Resource exhaustion — timeouts can be circumvented (see below)
  • Memory/disk consumption — unbounded allocations are possible

Real isolation requires a container (Docker/Podman) or VM. awrepl is a session manager, not a sandbox. Shipping something that looks like a sandbox and is not would be actively dangerous — so this is stated plainly.

Use awrepl only:

  • In trusted environments (your own machine, internal tools)
  • When running code you wrote or thoroughly reviewed
  • Behind proper auth and network boundaries if exposed as a service
  • With resource limits imposed at the OS/container level if needed

If you need to run untrusted code, use a container or virtual machine. Do not rely on awrepl alone.


API

ReplSession

A persistent Python interpreter backed by a subprocess worker.

from awrepl import ReplSession, ExecResult

session = ReplSession(
    session_id="my-session",
    timeout_ms=30000,           # per-call timeout
    max_output_bytes=65536,     # output cap before truncation
)

# Execute code
result: ExecResult = session.execute("x = [1, 2, 3]")

ExecResult fields:

  • stdout (str): Captured stdout
  • stderr (str): Captured stderr
  • value (str|None): repr() of the last expression, if any
  • exception (str|None): Error message if execution failed
  • traceback (str): Full traceback on exception
  • duration_ms (float): Wall-clock time for execution
  • truncated (bool): Output was truncated due to size limit
  • truncated_bytes (int): How many bytes were dropped

Methods:

# Execute code in the persistent namespace
result = session.execute("code", timeout_ms=30000)

# Get all bound variables (type and short repr)
variables: dict[str, str] = session.variables()
# {"x": "list: [1, 2, 3]", "name": "str: 'Alice'"}

# Inspect a single variable (type, repr, docstring, etc.)
info: dict = session.inspect("x")
# {"type": "list", "repr": "[1, 2, 3]", "dir": [...], "len": 3}

# Clear all user-defined variables (keeps builtins)
session.reset()

# Close the session and terminate the worker
session.close()

# Use as a context manager
with ReplSession("temp") as s:
    s.execute("x = 42")

SessionPool

Manage multiple REPL sessions indexed by ID.

from awrepl import SessionPool

pool = SessionPool(timeout_ms=30000, max_output_bytes=65536)

# Create a session (auto-generate ID)
sid1 = pool.create_session()

# Create a session with a custom ID
sid2 = pool.create_session("agent-2")

# Get a session
session = pool.get_session(sid2)
session.execute("x = 42")

# List all session IDs
sessions = pool.list_sessions()

# Delete a session
pool.delete_session(sid1)

# Close all sessions
pool.close_all()

Each session has its own namespace — one agent's variables don't affect another.


CLI

# Execute code once (ephemeral session)
awrepl run "print(1 + 2)"

# Use a persistent session across multiple calls
awrepl --session myagent run "x = 42"
awrepl --session myagent run "print(x)"  # Prints 42

# Output as JSON
awrepl run "42" --json
# {"stdout": "", "stderr": "", "value": "42", "exception": null, ...}

# Interactive REPL (basic, stdin-based)
awrepl serve

# Session-based interactive REPL
awrepl --session agent serve

# Verify the REPL contract (no network required)
awrepl --self-test

Options:

  • --session ID — Use a specific session (creates if needed)
  • --json — Output result as JSON
  • --traceback — Show full traceback on exception

How it works

awrepl runs a Python subprocess (python -i-style worker) and communicates via JSON over pipes. The worker:

  • Maintains a single persistent namespace
  • Executes code and captures stdout/stderr
  • Handles timeouts and output truncation
  • Survives syntax errors and exceptions

Multiple ReplSession instances can run in parallel, each with its own worker subprocess, enabling concurrent agents to maintain separate state.

Why subprocess, not in-process exec()?

  • In-process execution lets agent code crash or corrupt the host process
  • Subprocess isolation means a fatal error in agent code doesn't kill the agent
  • Each session gets its own Python interpreter with its own memory space
  • Timeouts are more reliable (can interrupt the subprocess)

Platform support: Linux, macOS, Windows (tested on all three). Uses only Python standard library — no external dependencies.


--self-test

Every install can prove the contract, with no service and no network:

$ awrepl --self-test
  PASS  Variables persist across calls
  PASS  Syntax error doesn't kill session
  PASS  Exception doesn't kill session
  PASS  Output truncation works
  PASS  variables() lists bound names
  PASS  Pool sessions are isolated

SELF-TEST: awrepl ok (6/6)

The test asserts:

  1. Variables defined in one call are readable in another (the whole point)
  2. A syntax error doesn't terminate the session
  3. An exception is reported, but the session survives
  4. Output longer than max_output_bytes is truncated with a flag
  5. variables() lists bound names correctly
  6. Sessions in a pool don't see each other's variables

The bug this package exists to prevent

An agent with access to a live object can look at it instead of guessing about it from memory.

Without awrepl:

# Agent's turn 1: I ran this, but I don't remember the result
code = "data = load_json('config.json')"
result = subprocess.run(["python", "-c", code])
# Stdout gone, no access to `data`

# Agent's turn 2: Guess based on memory (but agent memory is compressed/forgotten)
# "What was in that file again? Let me re-run the whole thing..."

With awrepl:

# Agent's turn 1: Run code, data persists
session.execute("data = load_json('config.json')")

# Agent's turn 2: Look at it
vars = session.variables()  # {"data": "dict: {...}"}
info = session.inspect("data")  # {"type": "dict", "len": 5, "keys": [...]}

Cuts through the memory layer. What you ask is what you get.


Limitations and design choices

Timeouts: The timeout_ms parameter exists, but relies on the subprocess signal handler. Some heavy operations (deep recursion, infinite loops in C extensions) may not be interruptible. Use OS-level resource limits (cgroups, ulimit) for hard guarantees.

Namespace pollution: The namespace persists, so a large object assigned to x stays in memory until reset() or the session closes. Plan for that.

No remote execution: This is a local subprocess REPL. For distributed execution, wrap it in an HTTP service or use it alongside a message queue.


The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl (you are here) what the agent believes the value is the value, printed from the live session
awresearch a summary of pages nobody opened every claim against the source it came from

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awm A portable, scoped agent memory docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awnest Prove there is a human before you let them into the nest docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awmail Give an agent an email address — send, and actually receive docs
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl (you are here) A REPL an agent can actually use — state that survives between turns docs
awresearch Ask a research question, get a cited report you can check docs

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

awrepl-0.1.0.tar.gz (26.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

awrepl-0.1.0-py3-none-any.whl (19.4 kB view details)

Uploaded Python 3

File details

Details for the file awrepl-0.1.0.tar.gz.

File metadata

  • Download URL: awrepl-0.1.0.tar.gz
  • Upload date:
  • Size: 26.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for awrepl-0.1.0.tar.gz
Algorithm Hash digest
SHA256 36938430c65cb916e7173e4f97c321c5ff49769d7d22bf0211b5f68775889eb1
MD5 68224c47b12b5f4e1977d9bb7a48fd98
BLAKE2b-256 77c4011ee32ae94811c3023ab5d889380d9f9112509a7f580c9875ec6d317fa4

See more details on using hashes here.

File details

Details for the file awrepl-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: awrepl-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 19.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for awrepl-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 594aaa5b8e9e2ed803f96481c97fdacfefa72389c7df6e2094523f13f6a69f20
MD5 15abf67cae6982653a9a3d3a589a3d93
BLAKE2b-256 a54e9f2e52cace3f69d7f45b67a235a65108aa5edb17fa26f3499658c6411992

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page