Expose one bounded execution tool
LangChain turns typed functions into tools with its @tool decorator; the function docstring describes the tool to the model. The official tool documentation covers schemas and runtime context. For code execution, make the function an adapter to a separate execution service rather than running generated code in the agent process.
The adapter below accepts source code but fixes the profile and timeout in application code. Workspace identity, credentials and ownership should come from an authenticated application context. The backend interface is a contract for your implementation, not an executable cpuOS SDK bundled with this site.
from typing import Protocolfrom langchain.tools import toolclass ExecutionBackend(Protocol): def run_python(self, source: str, timeout_seconds: int) -> dict: ... # Implement against your connected execution service.def make_code_tool(backend: ExecutionBackend): @tool def run_python(source: str) -> dict: """Run bounded Python analysis and return its execution result.""" if len(source.encode("utf-8")) > 32_000: return {"error": "Source exceeds the tool input limit"} result = backend.run_python(source, timeout_seconds=30) return { "exit_code": result["exit_code"], "stdout": result.get("stdout", "")[-4000:], "stderr": result.get("stderr", "")[-2000:], } return run_pythoncpuOS is in early access. @cpuos/sdk and cpuos snippets illustrate a proposed API contract, not publicly released packages. Confirm access and SDK versions with the team before using them; names may change.
Bind the tool to a user task
Build the backend adapter for the authenticated workspace and conversation. The model should not choose another user's sandbox ID or raise its own resource limits. Associate each tool call with a task ID, and reject calls after the task has completed or its runtime lease has expired.
- Prepare a Python profile with a pinned environment and only the task's inputs.
- Return provisioning failure, timeout and process failure as distinct results.
- Write artifacts to an approved output directory and return a manifest instead of arbitrary guest paths.
- Use the LangGraph page when the workflow needs graph state, checkpointing and controlled transitions between agent steps.
Test the adapter before adding an agent loop
Invoke the tool directly with a deterministic script, then test a syntax error, a timeout and an unavailable backend. Confirm that a request is not reported as successful until the execution service returns a result. Bound retries and total tool calls so the agent cannot create an unlimited execution bill.
The model itself can run on gpuOS or another tool-capable provider. Keep model credentials outside the execution environment, and send only the bounded result back into context. See the safe execution guide for the isolation and policy around the adapter.
Official documentation: docs.langchain.com/oss/python/langchain/tools