Optional add-on
Optional: Code Interpreter
Give the agent a sandboxed Python environment so it computes answers instead of guessing at arithmetic.
The “Numbers, Not Prose” request
Alice wants more than counts: “What's the average and median team size per department?” SQL gets the rows; models are unreliable at arithmetic. AgentCore Code Interpreter runs model-written Python in an isolated sandbox, so the agent can compute without touching your runtime.
What the platform provisions for you
ENABLE_CODE_INTERPRETER=trueuv run bootcamp.py deploy- Session permissions for your agent role on the AWS-managed
aws.codeinterpreter.v1 - The
run_pythontool, handed to your orchestrator automatically
Flags default to false and need stage 4 or higher. uv run bootcamp.py status shows CODE_INTERPRETER_ENABLED and BROWSER_ENABLED.
What you do as a developer
Read the tool
phase2/app/agent/sandbox_tools.py@tool def run_python(code: str) -> str: """Execute Python code in a secure AgentCore Code Interpreter sandbox and return its output. Use it for calculations, statistics and data transformations. print() every value you need to see. Args: code: Python source code to run. """ with code_session(REGION, identifier=CODE_INTERPRETER_ID) as client: return stream_text(client.execute_code(code))[:OUTPUT_LIMIT]One call, one fresh sandbox session:
code_sessionfrombedrock_agentcore.toolsstarts it and stops it when the block exits.terminaluv run bootcamp.py invoke "Use the code interpreter to compute the mean of 3, 5 and 10." --actor alice-chenAdd a data-analysis specialist
Challenge
The orchestrator can call
run_python, but it has no data. Add ananalysis_agentspecialist that fetches rows through the Gateway and then computes withrun_python, and register it with the orchestrator.Hint 1
It's the agents-as-tools pattern again. Look at
data_agentinbuild_specialists: a@toolthat builds anAgent. AgentCore Code Interpreter docs.Hint 2
Import
run_pythonfromsandbox_toolsand give the specialisttools=[*gateway_tools, run_python]. Tell it: query first, then compute, print every result, report numbers rather than code. Return it frombuild_specialists.Solution
phase2/app/agent/agent.py (inside build_specialists)from sandbox_tools import run_python @tool def analysis_agent(question: str) -> str: """Analyse DataStream data with Python: statistics, distributions, trends. Use for anything beyond one SQL answer. Args: question: The analysis to perform. """ agent = Agent( model=make_model(), system_prompt=( "You are a data analyst. First fetch the rows you need with the database tool, " "then compute with run_python (print every result). Report numbers, not code." ), tools=[*gateway_tools, run_python], hooks=[ReadOnlyGuardHook()], callback_handler=None, ) return str(agent(question))Return
[data_agent, weather_agent, analysis_agent]and add a routing line toorchestrator_prompt.Deploy and ask for analysis
terminaluv run bootcamp.py deploy uv run bootcamp.py invoke "What is the average and median team size per department?" --actor alice-chenExperiments
- Look at the trace in GenAI Observability: how many
run_pythoncalls did one question take, and how long did each sandbox session last? - Each call gets a fresh session. What does that mean for code that builds on a previous call's variables?
- What could go wrong if model-written code ran inside your runtime instead?
- Look at the trace in GenAI Observability: how many
Check your work
With ENABLE_CODE_INTERPRETER=true, the stage 4 checks include an extra code interpreter tool check (the agent must compute the mean of [3, 5, 10] = 6 with run_python):
uv run bootcamp.py test --only 4[PASS] stage 4 ...
[PASS] stage 4 code interpreter tool: The mean of [3, 5, 10] is 6.uv run bootcamp.py invoke "Use the code interpreter to compute the mean of 3, 5 and 10." --actor alice-chenExpected answer: 6, and a run_python span in the trace.
Under the hood
Both tools use the AWS-managed built-ins aws.codeinterpreter.v1 and aws.browser.v1. Every call starts a fresh, isolated sandbox session and stops it afterwards, so nothing leaks between participants or requests. When a flag is on, your agent role gets only the session permissions it needs, in the inline policy awsworkshop-<you>-sandbox-tools; the platform sets CODE_INTERPRETER_ENABLED / BROWSER_ENABLED on the runtime, and optional_tools() plus prompt_hints() hand the tools to the orchestrator with a one-line usage hint each.
def optional_tools() -> list:
"""The sandbox tools this runtime is configured for (empty when both capabilities are off)."""
tools = []
if capability_enabled("CODE_INTERPRETER_ENABLED"):
tools.append(run_python)
if capability_enabled("BROWSER_ENABLED"):
tools.append(browse_web)
return tools