plimsoll home · All integrations

plimsoll in Agno

PlimsollTools gives an Agno agent one tool, plimsoll_run_code, that runs the model's Python or JavaScript in a fresh plimsoll sandbox and tells the model whether the code ran, failed, or was refused before it could run.

Agno: an open-source Python framework for building agents, in which a toolkit groups the tools an agent may call. Agno (EXTERNAL · official docs ↗)

The Professor (a fictional narrator)

The model writes the program, Agno makes the call, and plimsoll supplies the room with no windows and no internet. Everyone gets the job they are suited for.

Real quote

Geoffrey Hinton: “It's a trillion real numbers and nobody quite knows how they work.”

StarTalk, 28 February 2026, at 52:01, on what a large language model is. StarTalk video at 52:01 (EXTERNAL · video ↗)

Wire it up

pip install 'plimsoll-client[agno]'
from agno.agent import Agent
from plimsoll_client import Client
from plimsoll_client.agno import PlimsollTools
from plimsoll_client.execution import CodeExecutor

executor = CodeExecutor(Client("https://plimsoll.internal:8746", token=TOKEN))
agent = Agent(model=..., tools=[PlimsollTools(executor)])

Options, limits and errors: Python client guide, Agno and CrewAI tools (EXTERNAL · source repo ↗)

Follow one call

Replay a recorded scenario. The diagram lights each hop the call passes; a refused call stops where it is refused. These buttons send no execution requests. Each answer's source states how it was recorded, including any fixture used. Exception panels show what reached the application, rather than an invented code result.

The modelasks for plimsoll_run_codeSTOPPED HEREMAY HAVE RUNThe language model decides to run code and writes the arguments: the code, its language and any input files.AgnoFunctionCallSTOPPED HEREMAY HAVE RUNAgno checks the model's arguments against the tool's schema (the language list included) and calls the tool; a call that does not fit the schema stops here.PlimsollToolsplimsoll_run_codeSTOPPED HEREMAY HAVE RUNChecks the arguments, hands them to the executor, and turns whatever comes back into the JSON the model reads: ran true, false or "unknown".CodeExecutorchecks, then sendsSTOPPED HEREMAY HAVE RUNAsks the daemon what it is, refuses if its isolation tier is below the floor or it lacks the language, then sends the code and files as one fresh project with a fixed command.plimsolldadmits or refusesSTOPPED HEREMAY HAVE RUNChecks the floor again against its current evidence, admits the run if it has capacity, and states a run record of exactly what it ran and answered.Fresh sandboxruns, then is deletedSTOPPED HEREMAY HAVE RUNA new locked-down container with no network: the files are written, the code runs once, and the container is removed.The modelasks for plimsoll_run_codeSTOP?The language model decides to run code and writes the arguments: the code, its language and any input files.AgnoFunctionCallSTOP?Agno checks the model's arguments against the tool's schema (the language list included) and calls the tool; a call that does not fit the schema stops here.PlimsollToolsplimsoll_run_codeSTOP?Checks the arguments, hands them to the executor, and turns whatever comes back into the JSON the model reads: ran true, false or "unknown".CodeExecutorchecks, then sendsSTOP?Asks the daemon what it is, refuses if its isolation tier is below the floor or it lacks the language, then sends the code and files as one fresh project with a fixed command.plimsolldadmits or refusesSTOP?Checks the floor again against its current evidence, admits the run if it has capacity, and states a run record of exactly what it ran and answered.Fresh sandboxruns, then is deletedSTOP?A new locked-down container with no network: the files are written, the code runs once, and the container is removed.

The model asks for

The tool answers the model

The Professor (a fictional narrator)

Each step of the call

  1. The model: The language model decides to run code and writes the arguments: the code, its language and any input files.
  2. Agno: Agno checks the model's arguments against the tool's schema (the language list included) and calls the tool; a call that does not fit the schema stops here.
  3. PlimsollTools: Checks the arguments, hands them to the executor, and turns whatever comes back into the JSON the model reads: ran true, false or "unknown".
  4. CodeExecutor: Asks the daemon what it is, refuses if its isolation tier is below the floor or it lacks the language, then sends the code and files as one fresh project with a fixed command.
  5. plimsolld: Checks the floor again against its current evidence, admits the run if it has capacity, and states a run record of exactly what it ran and answered.
  6. Fresh sandbox: A new locked-down container with no network: the files are written, the code runs once, and the container is removed.

How thick should the walls be?

The executor carries a floor; the daemon states its isolation tier. This picker is a teaching simulation: change either to see whether the tier meets the floor. It sends no request and does not check other capabilities.

The Professor (a fictional narrator)

The executor's floor defaults to kernel: docker under runc is the container tier and refuses every call until it runs gVisor, or the executor is built with an explicit container floor, which is for development on your own code only. Use the spelling shown in this page's wiring example.

Surprises and limits

Agno takes the name filesAgno passes media to tools through a parameter called files, and drops any tool parameter of that name from the schema without a warning. The model would never see it. The tool's parameter is input_files.
The default floor refuses plain DockerCodeExecutor's floor is kernel. A daemon on docker under runc is the container tier and refuses every call until it runs gVisor, or until the executor is built with minimum_isolation="container", which is for development on your own code only.
Nothing persists between callsEvery call is a fresh sandbox: no variable, import or file from an earlier call is there. The tool's description says so, so the model writes each call complete.
Only the libraries built into the imageThe sandbox has no network and installs nothing. Bake what models may import into the daemon's project image (plimsoll/sandbox-python carries NumPy and SciPy).
Cancelling an async run cancels the callagent.arun runs the tool in a worker thread with a cancel handle, which cancelling the await cancels too. Cancelled before the run request is sent (while the daemon is still answering Describe, say), the call never sends it. Cancelled while the run is in flight, its connection is cut and the thread ends at once rather than at the executor's timeout. The code may have run by then; the daemon stops it only if its provider honors the closed connection.