
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
@useatlas/e2b
Advanced tools
E2B Firecracker microVM (managed) sandbox for the explore tool.
bun add @useatlas/e2b e2b
import { defineConfig } from "@atlas/api/lib/config";
import { e2bSandboxPlugin } from "@useatlas/e2b";
export default defineConfig({
plugins: [e2bSandboxPlugin({ apiKey: process.env.E2B_API_KEY! })],
});
| Field | Type | Default | Description |
|---|---|---|---|
apiKey | string | — | E2B API key |
template | string? | default | Sandbox template ID |
timeoutSec | number | 30 | Command timeout in seconds |
pythonPackages | string[] | pandas, numpy, matplotlib, scipy, scikit-learn, statsmodels | Installed once per Python sandbox. Set to [] when your template already bakes them in |
This plugin implements the SDK's optional Python surface, so a workspace that
selects E2B runs both explore and executePython on its own E2B account.
A failure there is an error, not a fallback to the Atlas platform sandbox.
Egress: the host's per-request REST datasource egress bound is applied,
so the plugin declares pythonEgressControl: "enforced". Atlas's default for a
Python run is deny-all; when a REST datasource is active the bound narrows to
that datasource's hosts instead.
The plugin sets it with sandbox.updateNetwork (allowInternetAccess: false
for deny-all; allowOut paired with denyOut: ["0.0.0.0/0"] for an allowlist)
after pythonPackages are installed and before any agent code runs —
narrowing first would cut the sandbox off from PyPI.
⚠️ Requires the e2b SDK >= 2.45.0, the version this was verified against
and the peer range now requires. On a deployment whose SDK or backend refuses
the egress rules, executePython fails with a named error rather than running
unbounded; explore is unaffected. This bound is per sandbox and is in addition
to whatever your own VPC enforces on a BYOC deployment.
⚠️ A datasource on a non-standard port is worth confirming. Atlas derives the
allowlist from datasource hostnames (hostFromUrl strips the port), so E2B
receives a bare domain. E2B's own vendor docs describe domain rules as covering
ports 80/443; the 2.45.0 SDK schema states no port restriction on allowOut
either way, so this is not settled from the type definitions alone. If your REST
datasource listens on something else, verify egress reaches it before relying on
this — the failure mode is fail-closed (a connection timeout inside Python), not
an open sandbox.
FAQs
Atlas E2B sandbox plugin
We found that @useatlas/e2b demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.