Skip to content

✨ feat: update the sandbox preinstall libs in sys role#11688

Merged
ONLY-yours merged 1 commit intonextfrom
feat/updateCodeBoxSysRole
Jan 21, 2026
Merged

✨ feat: update the sandbox preinstall libs in sys role#11688
ONLY-yours merged 1 commit intonextfrom
feat/updateCodeBoxSysRole

Conversation

@ONLY-yours
Copy link
Copy Markdown
Member

@ONLY-yours ONLY-yours commented Jan 21, 2026

💻 Change Type

  • ✨ feat
  • 🐛 fix
  • ♻️ refactor
  • 💄 style
  • 👷 build
  • ⚡️ perf
  • ✅ test
  • 📝 docs
  • 🔨 chore

🔗 Related Issue

🔀 Description of Change

🧪 How to Test

  • Tested locally
  • Added/updated tests
  • No tests needed

📸 Screenshots / Videos

Before After
... ...

📝 Additional Information

Summary by Sourcery

Update the cloud sandbox system role to emphasize and enumerate pre-installed software and libraries, and to guide agents to prefer these over installing new packages.

New Features:

  • Document the operating system, runtimes, build tools, and key pre-installed Python and document/media libraries available in the cloud sandbox.
  • Add explicit instructions to prioritize pre-installed software and clarify which tools are not available and should not be used.

Enhancements:

  • Clarify Python and visualization usage guidelines to avoid unnecessary pip installs for pre-installed libraries like pandas and matplotlib.
  • Refine document generation instructions to distinguish between pre-installed and non-pre-installed libraries when deciding whether to install packages.

@vercel
Copy link
Copy Markdown

vercel bot commented Jan 21, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
lobehub Building Building Preview, Comment Jan 21, 2026 2:04pm

Request Review

@sourcery-ai
Copy link
Copy Markdown
Contributor

sourcery-ai bot commented Jan 21, 2026

Reviewer's Guide

Updates the cloud sandbox system role prompt to document and prefer a curated set of pre-installed OS, tools, and Python libraries, and adjusts Python execution guidance to avoid reinstalling those libraries and to clarify when pip installation is appropriate.

Flow diagram for Python library usage and installation in the sandbox

flowchart TD
  Start["Start Python task"] --> CheckPreinstalled["Check if required library is in preinstalled_software list"]

  CheckPreinstalled -->|"Library is pre-installed (e.g. numpy, scipy, pandas, matplotlib, plotly, scikit-learn, opencv-python, Pillow)"| UseDirect["Import and use library directly (no pip install)"]
  CheckPreinstalled -->|"Library is NOT pre-installed"| PipInstall["Run pip install for the missing library"]

  PipInstall --> RunCode["Run Python code using newly installed library"]
  UseDirect --> RunCode
Loading

Flow diagram for document generation tool and library selection

flowchart TD
  StartDoc["Start document generation task"] --> DetectFormat["Determine target file format"]

  DetectFormat -->|"DOCX"| UseDocx["Use python-docx (pip install if not pre-installed)"]
  DetectFormat -->|"XLSX"| UseXlsx["Use openpyxl (pip install if not pre-installed)"]
  DetectFormat -->|"PPTX"| UsePptx["Use python-pptx (pip install if not pre-installed)"]
  DetectFormat -->|"CSV"| UseCsv["Use pre-installed pandas directly (no installation)"]
  DetectFormat -->|"ODS/ODT/ODP"| UseOdf["Use odfpy (pip install if not pre-installed)"]

  UseDocx --> Export["Export generated document file"]
  UseXlsx --> Export
  UsePptx --> Export
  UseCsv --> Export
  UseOdf --> Export
Loading

File-Level Changes

Change Details Files
Document pre-installed sandbox software and establish guidelines to prefer these tools over installing new packages.
  • Add a <preinstalled_software> section to the system role prompt describing the OS, runtimes, and key pre-installed tools and libraries
  • Enumerate Python libraries like numpy, scipy, pandas, matplotlib, plotly, scikit-learn, opencv-python, Pillow with versions and usage notes
  • List available document/media tools, browser automation tools, and fonts, plus explicitly call out non-available tools such as Tesseract, Puppeteer, and mermaid-cli
  • Add installation guidelines instructing to only install extra packages when necessary and to prefer LibreOffice/Pandoc for document generation
packages/builtin-tool-cloud-sandbox/src/systemRole.ts
Align Python execution guidance with the pre-installed library set and clarify pip install behavior.
  • Add instructions to check the preinstalled_software section before installing Python libraries and to skip pip install for libraries already available
  • Explicitly note that numpy, scipy, pandas, matplotlib, plotly, scikit-learn, opencv-python, and Pillow are pre-installed and should be used directly
  • Clarify that matplotlib is pre-installed in the visualization guidelines and reinforce the prohibition on seaborn
  • Update file-format handling guidance so CSV uses pre-installed pandas and only non-preinstalled libraries should be installed with pip before use
packages/builtin-tool-cloud-sandbox/src/systemRole.ts

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@dosubot dosubot bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Jan 21, 2026
@ONLY-yours ONLY-yours merged commit 404c577 into next Jan 21, 2026
18 of 20 checks passed
@ONLY-yours ONLY-yours deleted the feat/updateCodeBoxSysRole branch January 21, 2026 14:04
@gru-agent
Copy link
Copy Markdown
Contributor

gru-agent bot commented Jan 21, 2026

⏳ Processing in progress

Copy link
Copy Markdown
Contributor

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Hard-coding specific version numbers in the system prompt (e.g., numpy 2.4.1, matplotlib 3.10.8) risks getting out of sync with the actual sandbox image; consider either omitting versions or generating this list from a single source of truth so the prompt stays accurate.
  • The description of wheel as a 'Python package installer' is misleading (it's a packaging format/tool rather than an installer like pip); updating this wording will avoid confusing downstream agents and users.
  • You now have two places describing pre-installed libraries (the new <preinstalled_software> section and the later Python/visualization/document guidelines); consider consolidating or explicitly cross-referencing them to reduce duplication and the chance of divergence.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- Hard-coding specific version numbers in the system prompt (e.g., numpy 2.4.1, matplotlib 3.10.8) risks getting out of sync with the actual sandbox image; consider either omitting versions or generating this list from a single source of truth so the prompt stays accurate.
- The description of `wheel` as a 'Python package installer' is misleading (it's a packaging format/tool rather than an installer like `pip`); updating this wording will avoid confusing downstream agents and users.
- You now have two places describing pre-installed libraries (the new `<preinstalled_software>` section and the later Python/visualization/document guidelines); consider consolidating or explicitly cross-referencing them to reduce duplication and the chance of divergence.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 50b2fafea7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +46 to +48
**Browser Automation:**
- Playwright - Browser automation
- marpc-cli - Browser-based PPTX generation
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fix likely typo in Marp CLI name

The preinstalled list now advertises marpc-cli as the PPTX tool, but I can’t find any other reference or installer for that name in the repo, so the system prompt will steer the agent to run a nonexistent command and fail. If this is meant to be Marp, the CLI is typically marp-cli, so the current spelling is likely a typo that will break PPTX generation flows.

Useful? React with 👍 / 👎.

@lobehubbot
Copy link
Copy Markdown
Member

❤️ Great PR @ONLY-yours ❤️

The growth of project is inseparable from user feedback and contribution, thanks for your contribution! If you are interesting with the lobehub developer community, please join our discord and then dm @arvinxx or @canisminor1990. They will invite you to our private developer channel. We are talking about the lobe-chat development or sharing ai newsletter around the world.

lobehubbot pushed a commit that referenced this pull request Jan 21, 2026
## [Version&nbsp;2.0.0-next.333](v2.0.0-next.332...v2.0.0-next.333)
<sup>Released on **2026-01-21**</sup>

#### ✨ Features

- **desktop**: Add legacy local database detection and migration guidance.
- **misc**: Update the sandbox preinstall libs in sys role.

#### 🐛 Bug Fixes

- **misc**: Fix multi tasks no summary issue.

<br/>

<details>
<summary><kbd>Improvements and Fixes</kbd></summary>

#### What's improved

* **desktop**: Add legacy local database detection and migration guidance, closes [#11682](#11682) ([5664b84](5664b84))
* **misc**: Update the sandbox preinstall libs in sys role, closes [#11688](#11688) ([404c577](404c577))

#### What's fixed

* **misc**: Fix multi tasks no summary issue, closes [#11685](#11685) ([26ce317](26ce317))

</details>

<div align="right">

[![](https://img.shields.io/badge/-BACK_TO_TOP-151515?style=flat-square)](#readme-top)

</div>
@lobehubbot
Copy link
Copy Markdown
Member

🎉 This PR is included in version 2.0.0-next.333 🎉

The release is available on:

Your semantic-release bot 📦🚀

JamieStivala pushed a commit to jaworldwideorg/OneJA-Bot that referenced this pull request Jan 23, 2026
## [Version&nbsp;1.153.0](v1.152.0...v1.153.0)
<sup>Released on **2026-01-23**</sup>

#### ♻ Code Refactoring

- **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable.
- **model-select**: Migrate FunctionCallingModelSelect to LobeSelect.
- **ModelSwitchPanel**: Migrate from Popover to DropdownMenu with virtual scrolling.
- **userMemories**: Removed un-used code.
- **misc**: Improve memory data with experience and identity, move vercel-react-best-practices skills to .agents directory.

#### ✨ Features

- **database**: Added user memory activity.
- **desktop**: Add legacy local database detection and migration guidance.
- **misc**: Add platform-aware download client menu option, add server version check for desktop app, remove Clerk authentication code, skill setting page and skill store, support agent group unpublish agents, support client tasks mode, update the sandbox preinstall libs in sys role.

#### 🐛 Bug Fixes

- **copilot**: Pass correct scope when creating new session in PageEditor.
- **desktop**: Gracefully handle missing update manifest 404 errors.
- **model-runtime**: Filter unsupported image types (SVG) before sending to vision models.
- **pdf**: Upgrade pdfjs-dist and react-pdf to v5.x.
- **sidebar-drawer**: Fix drawer positioning and title style.
- **misc**: Fix group broadcast trigger tool use, fix local system tools, fix memory schema, fix multi agent tasks issue, fix multi tasks no summary issue, fix scope issue, fix tool argument scape and improve multi task run, fixed the sandbox tools call when error should use right callback, improve e2e server and complete i18n resources, slove the agent group editor not focus in editdata area, slove the agents header switch agents the lobeAI not show problem, sloved the old removeSessionTopics not work, TypewriterEffect not refreshing on language change, updata cron job ui & fixed commnuity pagenation goto error, update the agentbuilder tools not always use humanIntervention.

#### 💄 Styles

- **misc**: Improve auto scroll and group profile, update og, update share style.

<br/>

<details>
<summary><kbd>Improvements and Fixes</kbd></summary>

#### Code refactoring

* **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable, closes [lobehub#11658](https://github.com/jaworldwideorg/OneJA-Bot/issues/11658) ([c0f9875](c0f9875))
* **model-select**: Migrate FunctionCallingModelSelect to LobeSelect, closes [lobehub#11664](https://github.com/jaworldwideorg/OneJA-Bot/issues/11664) ([ad51305](ad51305))
* **ModelSwitchPanel**: Migrate from Popover to DropdownMenu with virtual scrolling, closes [lobehub#11663](https://github.com/jaworldwideorg/OneJA-Bot/issues/11663) ([c9d9dff](c9d9dff))
* **userMemories**: Removed un-used code, closes [lobehub#11713](https://github.com/jaworldwideorg/OneJA-Bot/issues/11713) ([89750fc](89750fc))
* **misc**: Improve memory data with experience and identity, closes [lobehub#11717](https://github.com/jaworldwideorg/OneJA-Bot/issues/11717) ([bdb3eb4](bdb3eb4))
* **misc**: Move vercel-react-best-practices skills to .agents directory, closes [lobehub#11703](https://github.com/jaworldwideorg/OneJA-Bot/issues/11703) ([6df7731](6df7731))

#### What's improved

* **database**: Added user memory activity, closes [lobehub#11680](https://github.com/jaworldwideorg/OneJA-Bot/issues/11680) ([0160fbd](0160fbd))
* **desktop**: Add legacy local database detection and migration guidance, closes [lobehub#11682](https://github.com/jaworldwideorg/OneJA-Bot/issues/11682) ([5664b84](5664b84))
* **misc**: Add platform-aware download client menu option, closes [lobehub#11676](https://github.com/jaworldwideorg/OneJA-Bot/issues/11676) ([55abddc](55abddc))
* **misc**: Add server version check for desktop app, closes [lobehub#11710](https://github.com/jaworldwideorg/OneJA-Bot/issues/11710) ([0cf2723](0cf2723))
* **misc**: Remove Clerk authentication code, closes [lobehub#11711](https://github.com/jaworldwideorg/OneJA-Bot/issues/11711) ([395595a](395595a))
* **misc**: Skill setting page and skill store, closes [lobehub#11665](https://github.com/jaworldwideorg/OneJA-Bot/issues/11665) ([d8c0c26](d8c0c26))
* **misc**: Support agent group unpublish agents, closes [lobehub#11687](https://github.com/jaworldwideorg/OneJA-Bot/issues/11687) ([4e060be](4e060be))
* **misc**: Support client tasks mode, closes [lobehub#11666](https://github.com/jaworldwideorg/OneJA-Bot/issues/11666) ([98cf57b](98cf57b))
* **misc**: Update the sandbox preinstall libs in sys role, closes [lobehub#11688](https://github.com/jaworldwideorg/OneJA-Bot/issues/11688) ([404c577](404c577))

#### What's fixed

* **copilot**: Pass correct scope when creating new session in PageEditor, closes [lobehub#11714](https://github.com/jaworldwideorg/OneJA-Bot/issues/11714) ([0259270](0259270))
* **desktop**: Gracefully handle missing update manifest 404 errors, closes [lobehub#11625](https://github.com/jaworldwideorg/OneJA-Bot/issues/11625) ([13e95b9](13e95b9))
* **model-runtime**: Filter unsupported image types (SVG) before sending to vision models, closes [lobehub#11698](https://github.com/jaworldwideorg/OneJA-Bot/issues/11698) ([c0c99a7](c0c99a7))
* **pdf**: Upgrade pdfjs-dist and react-pdf to v5.x, closes [lobehub#11686](https://github.com/jaworldwideorg/OneJA-Bot/issues/11686) ([2b620df](2b620df))
* **sidebar-drawer**: Fix drawer positioning and title style, closes [lobehub#11655](https://github.com/jaworldwideorg/OneJA-Bot/issues/11655) ([cf5320e](cf5320e))
* **misc**: Fix group broadcast trigger tool use, closes [lobehub#11646](https://github.com/jaworldwideorg/OneJA-Bot/issues/11646) ([831a9b3](831a9b3))
* **misc**: Fix local system tools, closes [lobehub#11702](https://github.com/jaworldwideorg/OneJA-Bot/issues/11702) ([6548fc7](6548fc7))
* **misc**: Fix memory schema, closes [lobehub#11645](https://github.com/jaworldwideorg/OneJA-Bot/issues/11645) ([3baf780](3baf780))
* **misc**: Fix multi agent tasks issue, closes [lobehub#11672](https://github.com/jaworldwideorg/OneJA-Bot/issues/11672) ([9de773b](9de773b))
* **misc**: Fix multi tasks no summary issue, closes [lobehub#11685](https://github.com/jaworldwideorg/OneJA-Bot/issues/11685) ([26ce317](26ce317))
* **misc**: Fix scope issue, closes [lobehub#11719](https://github.com/jaworldwideorg/OneJA-Bot/issues/11719) ([17adde8](17adde8))
* **misc**: Fix tool argument scape and improve multi task run, closes [lobehub#11691](https://github.com/jaworldwideorg/OneJA-Bot/issues/11691) ([b13bb8a](b13bb8a))
* **misc**: Fixed the sandbox tools call when error should use right callback, closes [lobehub#11721](https://github.com/jaworldwideorg/OneJA-Bot/issues/11721) ([e8fce68](e8fce68))
* **misc**: Improve e2e server and complete i18n resources, closes [lobehub#11678](https://github.com/jaworldwideorg/OneJA-Bot/issues/11678) ([d450dd9](d450dd9))
* **misc**: Slove the agent group editor not focus in editdata area, closes [lobehub#11677](https://github.com/jaworldwideorg/OneJA-Bot/issues/11677) ([9ac84e6](9ac84e6))
* **misc**: Slove the agents header switch agents the lobeAI not show problem, closes [lobehub#11726](https://github.com/jaworldwideorg/OneJA-Bot/issues/11726) ([f45f508](f45f508))
* **misc**: Sloved the old removeSessionTopics not work, closes [lobehub#11671](https://github.com/jaworldwideorg/OneJA-Bot/issues/11671) ([06d41e5](06d41e5))
* **misc**: TypewriterEffect not refreshing on language change, closes [lobehub#11657](https://github.com/jaworldwideorg/OneJA-Bot/issues/11657) ([ba30f46](ba30f46))
* **misc**: Updata cron job ui & fixed commnuity pagenation goto error, closes [lobehub#11700](https://github.com/jaworldwideorg/OneJA-Bot/issues/11700) ([42ad2a0](42ad2a0))
* **misc**: Update the agentbuilder tools not always use humanIntervention, closes [lobehub#11696](https://github.com/jaworldwideorg/OneJA-Bot/issues/11696) ([0d3017b](0d3017b))

#### Styles

* **misc**: Improve auto scroll and group profile, closes [lobehub#11725](https://github.com/jaworldwideorg/OneJA-Bot/issues/11725) ([550acc2](550acc2))
* **misc**: Update og, closes [lobehub#11709](https://github.com/jaworldwideorg/OneJA-Bot/issues/11709) ([01cf4e4](01cf4e4))
* **misc**: Update share style, closes [lobehub#11716](https://github.com/jaworldwideorg/OneJA-Bot/issues/11716) ([3c70dfa](3c70dfa))

</details>

<div align="right">

[![](https://img.shields.io/badge/-BACK_TO_TOP-151515?style=flat-square)](#readme-top)

</div>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released on @next size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants