# How to give CrewAI agents safe code execution CrewAI removed its CodeInterpreterTool; wrap Runtime's `sandbox_tools(sbx)` with CrewAI's `tool` and agents run code in a microVM. **Runtime replaces CrewAI's retired code execution with a full Linux machine per crew, from $0.03125 an hour for 2 vCPU and 4 GiB while agents talk.** CrewAI's docs now tell you to use a dedicated sandbox service for code execution. Runtime's four tools are typed Python functions, so CrewAI's own `tool` wraps them with no adapter, and every command runs in a Firecracker microVM with its own Linux kernel, where `pip install` works. `crewai` 1.15.22 was the current PyPI release on 25 September 2026; the tools ran in a crew's own loop with CrewAI 1.15 on 23 September 2026. ## What changed in CrewAI CrewAI's CodeInterpreterTool page, read on 25 September 2026, says the tool "has been removed from `crewai-tools`", and that "`allow_code_execution` and `code_execution_mode` parameters on Agent are also deprecated". In the 1.15.22 source, setting `allow_code_execution` logs that it "is deprecated and will be removed in v2.0". The old tool had three modes, which is why it went: | Old CodeInterpreterTool mode | How it ran code | The docs' warning | | ---------------------------- | -------------------------------------------- | ------------------------------------------------------------------ | | Docker (recommended) | A container on your machine | The container can access "the current working directory" | | Restricted Python | A limited interpreter when Docker is missing | Library installs blocked | | `unsafe_mode=True` | Directly on your host | "NOT RECOMMENDED FOR PRODUCTION" | | Runtime `sandbox_tools` | A microVM with its own kernel, in the cloud | Nothing of your machine is inside; network rules are host-enforced | ## Install ```bash no-run pip install -U crewai withruntime npx withruntime login ``` The login opens a browser approval, so there is no Runtime key to paste. A deployed crew reads `RUNTIME_API_KEY` instead. ## A crew with a sandbox ```python check from crewai import Agent, Crew, Task from crewai.tools import tool from withruntime import Sandbox from withruntime.tools import sandbox_tools def fix_tests() -> str: with Sandbox.create() as sbx: engineer = Agent( role="Engineer", goal="Make the test suite pass", backstory="You work in a Linux sandbox.", tools=[tool(f) for f in sandbox_tools(sbx)], ) task = Task(description="Run the tests and fix what fails.", expected_output="A summary", agent=engineer) return str(Crew(agents=[engineer], tasks=[task]).kickoff()) print(fix_tests()) ``` `sandbox_tools` is written without `from __future__ import annotations` because CrewAI builds each tool's argument schema from real annotations. The engineer gets `runtime_exec`, `runtime_read_file`, `runtime_write_file` and `runtime_list_files`, with relative paths under `/workspace`. ## Several agents, one machine or many Agents in a crew hand work to each other, and a shared sandbox makes that literal: the analyst's CSV is on the reviewer's disk. ```python check from crewai import Agent, Crew, Task from crewai.tools import tool from withruntime import Sandbox from withruntime.tools import sandbox_tools with Sandbox.create(timeout_seconds=1800) as sbx: tools = [tool(f) for f in sandbox_tools(sbx)] analyst = Agent(role="Analyst", goal="Produce clean numbers", backstory="Pandas expert.", tools=tools) reviewer = Agent(role="Reviewer", goal="Check the numbers", backstory="Sceptical statistician.", tools=tools) crew = Crew( agents=[analyst, reviewer], tasks=[ Task(description="Write /workspace/sales.csv with 12 months of sample data and a summary.", expected_output="The file path and a summary", agent=analyst), Task(description="Recompute the summary from /workspace/sales.csv and list any differences.", expected_output="A verdict", agent=reviewer), ], ) print(crew.kickoff()) ``` For agents that must not see each other's work, give each its own sandbox. To start them all from one prepared machine, set it up once and call `sbx.fork(count=3)`: three running copies with the installed packages and memory, each billed as its own sandbox ([images, volumes and snapshots](/docs/python#images-volumes-and-snapshots)). ## What the crew can do in the sandbox - **Install and run anything** Ubuntu 24.04 runs: Python 3.12, Node.js 24, Bun, git and gcc are there, and `sudo` works. - **Start a service** and share it: your code calls `sbx.previews.create(8501)` for a Streamlit report at a private HTTPS address ([previews](/docs/python#previews-and-the-desktop)). - **Wait for a person** with the machine parked: `sbx.pause()` keeps files, memory and processes for 1 to 365 days, and compute billing stops. - **Run notebook cells** through `sbx.interpreter.run(code)`, which keeps variables and returns charts as PNG, for a crew that reports with plots. ## Keep keys and spending safe - **Model keys stay in the crew's process.** The sandbox receives commands, not the LLM's credentials. - **`max_cost_micros`** on `Sandbox.create` refuses a sandbox whose first lease would cost more, and `timeout_seconds` with `on_lease_end="stop"` bounds its life. - **A daily spending limit** on the Runtime key caps a crew that loops: past it, creates, wakes and extensions fail with `spending_limit_reached`, and nothing is charged ([read-only keys and daily limits](/docs/security#read-only-keys-and-daily-limits)). - **A read-only key** lets a monitoring job see every sandbox and its cost without being able to start one. - **Egress rules.** `network={"internet": False}` for pure analysis, or an `allow` list of registries; the host enforces both ([turn off sandbox internet](/how-to/turn-off-sandbox-internet)). - **Secrets** for a database or API the crew's code calls reach the sandbox as a worthless placeholder; the host adds the value on HTTPS requests to the hosts you name ([secrets](/docs/security#secrets-sandboxes-never-see)). ## What it costs Runtime bills measured CPU at $0.025 per vCPU-hour, with a floor of a twentieth of a vCPU, plus $0.0075 per reserved GiB-hour. A crew mostly waits on model calls, and with both CPUs busy 2 vCPU and 4 GiB is still $0.08 an hour ([pricing](/docs/pricing)). New accounts get 50 free sandbox hours, no card. A crew that analyses data is close to [a data analysis agent](/use-cases/data-analysis-agent), and why a microVM beats a local container for model-written code is in [run untrusted LLM code](/use-cases/run-untrusted-llm-code). ## Sources Checked 25 September 2026. - [CrewAI CodeInterpreterTool](https://docs.crewai.com/en/tools/ai-ml/codeinterpretertool): the removal notice, the deprecated Agent parameters, the three execution modes and their warnings - [crewai 1.15.22 on PyPI](https://pypi.org/project/crewai/): the `allow_code_execution` deprecation message and the `tool` function that wraps a plain function Facts on this page were checked on 25 September 2026.