Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Sub-agent DAG nodes never get the sandbox executor: exec runs on the host with tools.sandbox enabled

Open
#796 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
68/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
python
Domain
backend, security

Research direction

Start with run_dag() in raven/agent/subagent/dag_runner.py around line 262 and SubAgentDagTool in raven/agent/subagent/dag_tool.py around line 2345. Compare the spawn paths where SubagentManager builds an executor, then verify how the sandbox reaches each DAG node backend. Done means a boxlite DAG node runs uname -s as Linux on macOS and the behavior is covered by a test.

Written by the indexing model from the issue text.

Description

Version: main @ e1769411 (Raven v0.2.1), macOS arm64, boxlite==0.9.5

Config: tools.sandbox = {"backend": "boxlite", "allow_net": false, "extra_volumes": [["<host dir>", "/data", "ro"]]}

What happens: every node of a sub-agent DAG (a mode: dag playbook, or a graph the model submits through run_subagent_dag) runs exec on the host, not in the sandbox VM. A node on the builtin Raven agent that runs pwd; ls /data prints the host workspace path and ls: /data: No such file or directory. The same command through spawn runs inside the VM.

Why: run_dag() takes sandbox: Any = None (raven/agent/subagent/dag_runner.py, signature around line 262) and hands it to each node backend, but SubAgentDagTool calls run_dag(...) (raven/agent/subagent/dag_tool.py, around line 2345) without passing sandbox, so the raven_loop node backend builds its ExecTool on DirectExecutor. SubagentManager builds a real executor with build_executor(self._sandbox_config, ...), but only on the spawn paths.

Why it matters: docs/sandbox/usage.md says Raven "does not silently fall back to host execution". Here it does, silently, on exactly the path most likely to process untrusted input in parallel. A node that reads attacker-controlled text gets a host shell.

Suggested fix: give SubAgentDagTool access to the manager's sandbox config and pass an executor into run_dag (or build one per node the way the spawn path does), and add a test that a DAG node's uname -s is Linux when backend is boxlite on macOS.

Dominant language
Python
Stars
4.1k
Forks
94
Avg merge
10h 2m
Merged PRs (30d)
376

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from EverMind-AI/Raven

All issues in EverMind-AI/Raven

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.