Safe code execution for agents: sandboxed Python/JS/bash, resource limits, output capture, dependency injection, timeout