Returns run_r_code and run_bash. Both run model-written code with your
user account's access. Each call runs in a separate process, which is not a
sandbox. permissions_standard() denies both tools; allow them with
r_code = TRUE and bash = TRUE in Permissions(). For an OS sandbox, use
tools_mcp_repl().
The processes don't inherit your environment variables, and R there
doesn't read .Renviron. They get the variables that locate programs,
libraries, locales and temporary files, such as PATH, HOME, LANG and
TMPDIR, plus the ones you name in env.
This keeps keys out of what the code is given, not out of its reach: code
running as your user account can still read your R session's starting
environment through the operating system, and any file your account can
read, .Renviron included. To keep keys from the code, run it under an
account that can't read them, or in a sandbox.
Examples
if (FALSE) { # \dontrun{
agent <- Agent$new(
chat = ellmer::chat("openai/gpt-6-luna"),
tools = tools_code(),
permissions = Permissions(r_code = TRUE, bash = TRUE)
)
} # }