haiku-skills-sandbox
Docker sandbox skill for haiku.skills. Executes Python code in an isolated Docker container with pre-installed data science packages and filesystem access.
Prerequisites
Build the Docker image (once):
docker build -t haiku-skills-sandbox:latest skills/sandbox/haiku_skills_sandbox/
Usage
Via entry point discovery
HAIKU_SKILLS_SANDBOX_WORKSPACE=/path/to/data haiku-skills chat
Programmatic
from pathlib import Path
from haiku_skills_sandbox import create_skill
skill = create_skill(
workspace=Path("/path/to/data"), # mounted at /workspace in the container
idle_timeout=1800, # stop container after 30min idle (default: 1h)
image="my-custom-image:latest", # custom Docker image (default: haiku-skills-sandbox:latest)
)
Configuration
| Parameter | Env var | Default | Description |
|---|---|---|---|
workspace |
HAIKU_SKILLS_SANDBOX_WORKSPACE |
None | Host directory mounted at /workspace in the container |
idle_timeout |
HAIKU_SKILLS_SANDBOX_IDLE_TIMEOUT |
3600 | Seconds of inactivity before the container is stopped |
image |
HAIKU_SKILLS_SANDBOX_IMAGE |
haiku-skills-sandbox:latest |
Docker image to use for the container |
Priority: create_skill() argument > environment variable > default.
Container lifecycle
- Containers start lazily on the first tool call
- Session binding via
SandboxState.session_id— the same AG-UI thread reuses the same container - Idle containers are stopped automatically (checked on each tool call)
- All containers are stopped on process exit via
atexit - When workspace is mounted, files persist on the host — restarting a container loses nothing
Pre-installed packages
The haiku-skills-sandbox:latest image includes: pandas, numpy, scipy, matplotlib.
Security considerations
- Network access: Containers have full network access (Docker bridge networking) by default.
- Command execution:
ConsoleToolsetis configured withrequire_execute_approval=False— the LLM can run arbitrary commands inside the container without user confirmation. Docker provides the isolation boundary. - Workspace access: When a workspace is mounted, the container has full read/write access to that host directory. The LLM can read, modify, or delete any file in the mounted workspace.
- Container user: The container runs as root. Docker container isolation is the security boundary, not OS-level user separation.
Metadata
Release files for haiku-skills-sandbox 0.17.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| haiku_skills_sandbox-0.17.2.tar.gz | 3.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| haiku_skills_sandbox-0.17.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 8.9 kB
Release files / haiku_skills_sandbox-0.17.2.tar.gz
| Download URL | haiku_skills_sandbox-0.17.2.tar.gz |
|---|---|
| Size | 3.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f47641c868dee3c9f9b59a074e2b45bdb7911eb75a1aaa94d9cc8367f2c3dc7e
|
|
BLAKE2b-256 checksum How to use checksums |
795047f285beda4a679d23c0f6846a8318eb56d267be26684f011c3aa30277f7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.13
|
Release files / haiku_skills_sandbox-0.17.2-py3-none-any.whl
| Download URL | haiku_skills_sandbox-0.17.2-py3-none-any.whl |
|---|---|
| Size | 5.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
08bbd11144527d45448f4a873b0c3e749ce91106574cf63c92964bd5f8d20e4f
|
|
BLAKE2b-256 checksum How to use checksums |
ec5c3825b90c9ac74bb4fb8cbe1efe3fe3df342a6574880c796422446dc3d0fc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.13
|