Skip to main content

haiku-skills-sandbox

Docker sandbox skill for haiku.skills. Executes Python code in an isolated Docker container with pre-installed data science packages and filesystem access.

Prerequisites

Build the Docker image (once):

docker build -t haiku-skills-sandbox:latest skills/sandbox/haiku_skills_sandbox/

Usage

Via entry point discovery

HAIKU_SKILLS_SANDBOX_WORKSPACE=/path/to/data haiku-skills chat

Programmatic

from pathlib import Path
from haiku_skills_sandbox import create_skill

skill = create_skill(
    workspace=Path("/path/to/data"),  # mounted at /workspace in the container
    idle_timeout=1800,                # stop container after 30min idle (default: 1h)
    image="my-custom-image:latest",   # custom Docker image (default: haiku-skills-sandbox:latest)
)

Configuration

Parameter Env var Default Description
workspace HAIKU_SKILLS_SANDBOX_WORKSPACE None Host directory mounted at /workspace in the container
idle_timeout HAIKU_SKILLS_SANDBOX_IDLE_TIMEOUT 3600 Seconds of inactivity before the container is stopped
image HAIKU_SKILLS_SANDBOX_IMAGE haiku-skills-sandbox:latest Docker image to use for the container

Priority: create_skill() argument > environment variable > default.

Container lifecycle

  • Containers start lazily on the first tool call
  • Session binding via SandboxState.session_id — the same AG-UI thread reuses the same container
  • Idle containers are stopped automatically (checked on each tool call)
  • All containers are stopped on process exit via atexit
  • When workspace is mounted, files persist on the host — restarting a container loses nothing

Pre-installed packages

The haiku-skills-sandbox:latest image includes: pandas, numpy, scipy, matplotlib.

Security considerations

  • Network access: Containers have full network access (Docker bridge networking) by default.
  • Command execution: ConsoleToolset is configured with require_execute_approval=False — the LLM can run arbitrary commands inside the container without user confirmation. Docker provides the isolation boundary.
  • Workspace access: When a workspace is mounted, the container has full read/write access to that host directory. The LLM can read, modify, or delete any file in the mounted workspace.
  • Container user: The container runs as root. Docker container isolation is the security boundary, not OS-level user separation.

Metadata

Release files for haiku-skills-sandbox 0.17.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for haiku-skills-sandbox 0.17.2
File Size Uploaded
haiku_skills_sandbox-0.17.2.tar.gz 3.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for haiku-skills-sandbox 0.17.2
File Interpreter ABI Platform
haiku_skills_sandbox-0.17.2-py3-none-any.whl Python 3 none any Details

Total release size: 8.9 kB

Release files / haiku_skills_sandbox-0.17.2.tar.gz

Download URL haiku_skills_sandbox-0.17.2.tar.gz
Size 3.9 kB
Tags Source
SHA-256 checksum
How to use checksums
f47641c868dee3c9f9b59a074e2b45bdb7911eb75a1aaa94d9cc8367f2c3dc7e
BLAKE2b-256 checksum
How to use checksums
795047f285beda4a679d23c0f6846a8318eb56d267be26684f011c3aa30277f7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.13

Release files / haiku_skills_sandbox-0.17.2-py3-none-any.whl

Download URL haiku_skills_sandbox-0.17.2-py3-none-any.whl
Size 5.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
08bbd11144527d45448f4a873b0c3e749ce91106574cf63c92964bd5f8d20e4f
BLAKE2b-256 checksum
How to use checksums
ec5c3825b90c9ac74bb4fb8cbe1efe3fe3df342a6574880c796422446dc3d0fc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.13

Release history Release notifications | RSS feed

This release

0.17.2 This release

2 release files

0.17.0

2 release files

0.15.0

2 release files

0.13.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page