New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

@useatlas/e2b

Package Overview
Dependencies
Maintainers
1
Versions
5
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@useatlas/e2b

Atlas E2B sandbox plugin

latest
Source
npmnpm
Version
0.0.7
Version published
Maintainers
1
Created
Source

@useatlas/e2b

E2B Firecracker microVM (managed) sandbox for the explore tool.

Install

bun add @useatlas/e2b e2b

Usage

import { defineConfig } from "@atlas/api/lib/config";
import { e2bSandboxPlugin } from "@useatlas/e2b";

export default defineConfig({
  plugins: [e2bSandboxPlugin({ apiKey: process.env.E2B_API_KEY! })],
});

Config

FieldTypeDefaultDescription
apiKeystringE2B API key
templatestring?defaultSandbox template ID
timeoutSecnumber30Command timeout in seconds
pythonPackagesstring[]pandas, numpy, matplotlib, scipy, scikit-learn, statsmodelsInstalled once per Python sandbox. Set to [] when your template already bakes them in

Python execution

This plugin implements the SDK's optional Python surface, so a workspace that selects E2B runs both explore and executePython on its own E2B account. A failure there is an error, not a fallback to the Atlas platform sandbox.

Egress: the host's per-request REST datasource egress bound is applied, so the plugin declares pythonEgressControl: "enforced". Atlas's default for a Python run is deny-all; when a REST datasource is active the bound narrows to that datasource's hosts instead.

The plugin sets it with sandbox.updateNetwork (allowInternetAccess: false for deny-all; allowOut paired with denyOut: ["0.0.0.0/0"] for an allowlist) after pythonPackages are installed and before any agent code runs — narrowing first would cut the sandbox off from PyPI.

⚠️ Requires the e2b SDK >= 2.45.0, the version this was verified against and the peer range now requires. On a deployment whose SDK or backend refuses the egress rules, executePython fails with a named error rather than running unbounded; explore is unaffected. This bound is per sandbox and is in addition to whatever your own VPC enforces on a BYOC deployment.

⚠️ A datasource on a non-standard port is worth confirming. Atlas derives the allowlist from datasource hostnames (hostFromUrl strips the port), so E2B receives a bare domain. E2B's own vendor docs describe domain rules as covering ports 80/443; the 2.45.0 SDK schema states no port restriction on allowOut either way, so this is not settled from the type definitions alone. If your REST datasource listens on something else, verify egress reaches it before relying on this — the failure mode is fail-closed (a connection timeout inside Python), not an open sandbox.

Reference

  • Plugin SDK docs
  • Authoring guide

Keywords

atlas

FAQs

Package last updated on 30 Aug 2026

Related posts