Make E2B Code Execution
Use this skill when the user wants code to become a durable tool.
Known E2B module id: the E2B sandbox module is "module": "e2b:RunE2BSandbox" with "version": 0.
The architecture is:
Hermes writes code -> Code folder -> local execution or Make E2B Code Shell -> E2B runtime
If that code needs SaaS data, it must call a Make API shell scenario from
make-api-shell-connection-workflow. Do not put OAuth secrets, Make API tokens,
E2B API keys, refresh tokens, provider passwords, or direct provider SDK auth in
generated code.
Storage Rule
Store all durable code artifacts below the configured Hermes Code folder:
- local knowledge store:
knowledge/hermes/Code/... - Google Drive knowledge store:
/Hermes/Code/...
Use the runtime helper, for example:
import make_api_shell as make
make.write_code_artifact(
"tools/calc.py",
"print(17 * 23)\\n",
language="python",
confirm=True,
)
Do not write durable code files directly with shell redirection, open(...), or
Path.write_text(...) unless the user explicitly asked for a temporary local
scratch file.
Execution Modes
Plain Code Execution
Use this for quick, non-hosted code:
- Write the code artifact under
Code/. - Run it with the local
code_executiontool. - Write a short run note or output artifact only through the configured Knowledge helper.
Hosted E2B Code Shell
Use this when the code should become a reusable hosted tool:
- Write the code artifact under
Code/. - Create or reuse a Make scenario that matches the E2B Code Shell contract.
- Run the shell with
codePath,language,entrypoint,input,mode, andtimeoutMs. - Treat the E2B shell output as the tool result.
The Make scenario is the control-plane shell. E2B is only the runtime. The agent never receives E2B credentials.
Building the shell on the verified e2b Make app (verified live)
When no infrastructure runner URL is available, build the E2B Code Shell as an
app-action shell on the Make-verified app e2b ("e2b.dev", beta, major
version 0), module e2b:RunE2BSandbox:
- Module mapper fields:
execLanguage(python/javascript),inputFormat(string/base64),dependencies(array),timeoutSeconds(number, required),code(text, required). Map inputs from the standard shell interface as{{2.qs.<field>}}. - The connection comes from a credential request for
e2b/RunE2BSandbox. Bind it twice: as legacy__IMTCONN__(required by the shell verifier) and as the module's declared parameteraccount— manifest-2/SDK modules ignore__IMTCONN__and otherwise run without credentials. In helper environments passconnection_parameter="account"tocreate_app_action_shell_scenario. - Patch the scenario interface to the generic shell contract before the first run, then activate the scenario.
- The module's output field is
logswith shape{"stdout": ["..."], "stderr": []}— map ReturnData as{"data": "{{<moduleId>.logs}}"}(stdout/result/outputdo not exist and silently return null). Usereturn_field="logs"in helper environments. - Editing the scenario in the Make UI renumbers module ids and rewrites
the module parameters (dropping
__IMTCONN__). After any UI edit, re-read the blueprint, re-bind the connection both ways, and fix the ReturnData reference to the new module id — a stale reference returnsdata: nullon otherwise successful runs. - E2B error fingerprints from the module:
401: authorization header is missingmeans the module sent no key (connection not bound);401: authorization header is malformedmeans the stored apiKey does not start withe2b_— common causes: a "Bearer " prefix, quotes, thesk_e2b_...Access Token pasted instead of the API Key, or a UI save that silently did not persist (fix viaPOST /connections/{id}/set-data). The e2b app sendsX-API-Key: <apiKey>raw, so store the baree2b_...key.
Nested SaaS Access
For “inception” tools, generated code may call Make API shell scenarios:
Hosted code -> Make Gmail API shell -> Gmail API
The hosted code should receive only scenario IDs, paths, request payloads, and non-secret input data. It must never receive raw Make or provider credentials.