codecell
Stateless, subprocess-isolated code execution for LLM agents. Zero dependencies.
Unlike a Jupyter cell, there's no shared kernel — each call runs in a fresh subprocess with only the tools you inject.
Scope: codecell is intentionally limited to sandboxed code evaluation — safe computation and namespace-based tool invocation. It is not a full runtime or a general-purpose execution engine. Features like stateful sessions, IPC-based tool calling, and container isolation may be added in future versions.
Quick start
from codecell import SubprocessRuntime
from codecell.python import PythonValidator
runtime = SubprocessRuntime(PythonValidator())
result = runtime.execute("print(1 + 2)", timeout=10)
print(result.stdout) # "3\n"
Languages
Python (sandboxed)
AST-validated — blocks file I/O, network, command execution, dynamic imports. Only safe computation modules allowed.
from codecell import SubprocessRuntime
from codecell.python import PythonValidator
py = SubprocessRuntime(PythonValidator())
# Safe computation works
py.execute("import math; print(math.sqrt(16))")
# Dangerous code is rejected before execution
py.execute("import os; os.system('rm -rf /')") # raises ValueError
Bash (deny-list)
Regex-based deny list blocks known-dangerous patterns. Not a sandbox — reduces risk but cannot guarantee safety.
from codecell import SubprocessRuntime
from codecell.bash import BashValidator
bash = SubprocessRuntime(BashValidator())
bash.execute("echo hello && ls -la") # OK
bash.execute("rm -rf /") # raises ValueError
Trusted code (no validation)
from codecell import SubprocessRuntime, NullValidator
unsafe = SubprocessRuntime(NullValidator("python"))
unsafe.execute("import os; print(os.getpid())") # runs without validation
Namespace injection (Python only)
Inject callables into the execution namespace. In subprocess mode, they're available as stubs for discovery:
def search(query: str) -> list:
"""Search for documents."""
...
result = py.execute(
"print('search' in dir())",
namespace={"search": search},
)
# stdout: "True"
API
SubprocessRuntime(validator)
Execute code in a subprocess. The validator provides language identity and code validation.
runtime.execute(code, *, namespace=None, timeout=None) -> CodeResult
| Parameter | Type | Description |
|---|---|---|
code |
str |
Source code to execute |
namespace |
dict[str, Callable] | None |
Callables to inject (Python only) |
timeout |
float | None |
Max seconds before kill |
CodeResult
| Field | Type | Description |
|---|---|---|
stdout |
str |
Captured standard output (truncated at 64 KB) |
stderr |
str |
Captured standard error |
return_code |
int |
Exit code, -1 for timeout |
timed_out |
bool |
Whether killed by timeout |
Validators
| Validator | Security level | Language |
|---|---|---|
PythonValidator |
Strong (AST analysis) | Python |
BashValidator |
Best-effort (regex deny-list) | Bash |
NullValidator(lang) |
None — trusted code only | Any |
License
MIT
Metadata
Release files for codecell 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| codecell-0.2.1.tar.gz | 15.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| codecell-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 30.0 kB
Release files / codecell-0.2.1.tar.gz
| Download URL | codecell-0.2.1.tar.gz |
|---|---|
| Size | 15.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4a153e8f2116e0a0e314e7b00f0eeea304c73e3239cd3f9daac541a2ba0b2a42
|
|
BLAKE2b-256 checksum How to use checksums |
796588d8f6dba3187b550b131e5804e49b6fce2f99eb67af97af7b4e0da6fe2f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 2, 2026.
Transparency logRelease files / codecell-0.2.1-py3-none-any.whl
| Download URL | codecell-0.2.1-py3-none-any.whl |
|---|---|
| Size | 14.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8b9f2e591dc11b9c0a6494a46f543fd6b20fa79c218ba56faa87d8af42ac8446
|
|
BLAKE2b-256 checksum How to use checksums |
e19c667c1c9cef5f8f07bda37820cd1fb87c81a423a943d75164eeb2c0ecbf03
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 2, 2026.
Transparency log