Awesome Reviewers

Enforce security boundaries using robust validation and least-privilege isolation.

Example (path confinement):

from pathlib import Path

def resolve_safe(run_folder: Path, relative_path: str) -> Path:
    resolved = (run_folder / relative_path).resolve()
    run_resolved = run_folder.resolve()
    if not resolved.is_relative_to(run_resolved):
        raise ValueError("Path escapes run folder")
    return resolved

Example (sandbox hardening pattern):

import os, subprocess
from shared.credential_scrubber import scrub_credentials

result = subprocess.run(
    [
        "docker", "run", "--rm",
        "--cap-drop=ALL",
        f"--user={os.getuid()}:{os.getgid()}",
        "--memory=2g", "--cpus=2",
        "-v", f"{workspace.resolve()}:/workspace",
        "image", "bash", "-c", command,
    ],
    capture_output=True, text=True, timeout=timeout,
)
stdout = scrub_credentials(result.stdout)
stderr = scrub_credentials(result.stderr)