A custom tool for your crew
CrewAI's built-in code interpreter tool runs code in a local Docker container by default, and directly on the host in its unsafe mode. A custom tool that calls cpuos moves execution to a microVM on separate hardware, with egress rules and an audit log.
pip install crewai cpuosimport osfrom cpuos import Sandboxfrom crewai import LLM, Agent, Crew, Taskfrom crewai.tools import toolllm = LLM( model="openai/qwen3-32b", base_url="https://gpuos.si/v1", api_key=os.environ["GPUOS_API_KEY"],)sbx = Sandbox.create(template="python", timeout="30m")@tool("run_python")def run_python(code: str) -> str: """Run a Python 3 script in an isolated sandbox. Files live in /work. Returns the exit code, stdout and stderr.""" sbx.files.write("/work/main.py", code) run = sbx.exec("cd /work && python main.py", timeout="2m") return f"exit_code={run.exit_code}\n{run.stdout[-4000:]}\n{run.stderr[-2000:]}"analyst = Agent( role="Data analyst", goal="Answer questions with numbers you computed yourself", backstory="You never guess a number. You run code to check it.", tools=[run_python], llm=llm,)task = Task( description="Load /work/orders.csv and find the top 3 customers by revenue.", expected_output="A short table of customers and revenue.", agent=analyst,)with open("orders.csv", "rb") as f: sbx.files.write("/work/orders.csv", f.read())print(Crew(agents=[analyst], tasks=[task]).kickoff())sbx.pause()The openai/ prefix tells CrewAI, which routes model calls through LiteLLM, to use the OpenAI-compatible protocol at base_url.
The examples point the model at gpuOS, which serves open models on your own GPUs at https://gpuos.si/v1 with an OpenAI-compatible API. Any other OpenAI-compatible provider works the same way: change the base URL, the key and the model name.
cpuos is in early access: @cpuos/sdk (npm) and cpuos (PyPI) ship to early-access teams first, and read the API key from CPUOS_API_KEY. The calls on this page show the current API shape.
Official documentation: www.crewai.com