Creates a dsprrr code runner backed by Posit's
mcp-repl MCP server.
mcp-repl keeps a long-lived R session and enforces its sandbox with
operating-system primitives. This makes it suitable for code proposed by an
optimizer or language model.
Usage
mcp_repl_runner(
repl = NULL,
command = "mcp-repl",
interpreter = "r",
sandbox = "workspace-write",
timeout = 30,
max_output_chars = 100000L,
oversized_output = "files",
extra_args = character()
)Arguments
- repl
Optional function implementing the mcp-repl
repltool.- command
Path or command name for the
mcp-replexecutable.- interpreter
Interpreter passed to mcp-repl. Currently only
"r"is supported by this runner.- sandbox
mcp-repl sandbox policy. Defaults to
"workspace-write"."inherit-codex"may be used only when the MCP client propagates Codex sandbox metadata;mcptools::mcp_tools()does not currently do so.- timeout
Maximum execution time in seconds.
- max_output_chars
Maximum number of output characters returned to the optimizer.
- oversized_output
mcp-repl oversized-output mode.
- extra_args
Additional command-line arguments passed to mcp-repl.
Details
By default, mcp_repl_runner() starts mcp-repl through
mcptools::mcp_tools() with:
the R interpreter;
the
workspace-writesandbox;network access disabled by the sandbox; and
oversized output written to sandbox-visible files.
The sandbox is deliberately on by default. Setting sandbox = "off" is
rejected because this runner advertises itself as safe for untrusted code.
Use r_code_runner() explicitly for trusted-input-only subprocess
isolation.
Supplying repl is useful for an already-managed MCP connection and for
deterministic tests. It must be a function with the mcp-repl tool contract:
repl(input, timeout_ms).