Skip to main content
A data analysis agent runs generated Python, installs libraries, reads customer files, and creates charts or reports. The runtime needs strict data scope and predictable resource limits even when the code appears harmless. Updated October 9, 2026. Mount or copy only the approved dataset into a fresh sandbox and export only reviewed artifacts.

Separate session data

Create a unique prefix or bucket access point for each session. The sandbox role should read only approved inputs and write only to its output prefix. Do not give a shared analytics role broad access to every customer’s S3 objects. Avoid embedding raw datasets in model prompts when the analysis can run locally. Send the model schemas, summaries, or tool results needed for reasoning, then keep bulk processing inside the customer’s AWS boundary.

Build a reproducible runtime

Bake common Python, numerical, plotting, and file-format libraries into a versioned image. Allowing unrestricted pip install during every session adds supply-chain risk, latency, and non-reproducible dependencies. When dynamic packages are necessary, use an allowlisted proxy or internal package repository, pin versions and hashes, and record the resolved environment with the output.

Bound compute and storage

Set CPU, memory, ephemeral disk, process count, wall time, and output limits. CSV joins, decompression bombs, image rendering, and accidental cartesian products can exhaust resources without malicious intent. Fargate tasks can request expanded ephemeral storage within supported limits, but temporary disk is not durable. Upload notebooks, scripts, charts, and result files before the task exits.

Control data exfiltration

Disable public egress by default. If packages or external APIs are required, route through explicit endpoints. Do not let generated code reach metadata, internal databases, unrelated buckets, or arbitrary web hosts. Inspect artifact types and sizes before making them downloadable. Spreadsheet formulas, HTML reports, serialized Python objects, and archives can carry active or unsafe content.

Make results reproducible

Store the code, image digest, package lock, input object versions, random seeds, runtime limits, and execution timestamps with the result. A chart without its derivation is difficult to audit.

Springwinter fit

A Springwinter Worker can run trusted recurring analysis. Multi-tenant code-interpreter sessions should use one disposable task per session. Current Workers are long-lived services, so a controller must launch the actual sandbox through direct ECS, Batch, or another isolated execution system.

Frequently asked questions

Default to no. Add narrowly controlled egress only for required package registries or APIs. Generated code with open internet can exfiltrate source data through ordinary HTTP requests.
No. Validate types, size, provenance, and dangerous active content. Successful execution says nothing about analytical correctness or artifact safety.
Save selected code, environment metadata, input versions, logs, and approved artifacts. Delete the temporary filesystem and session credentials after retention requirements are met.

Sources and further reading

Last modified on October 8, 2026