LangChain CSV Agent报错:需设置allow_dangerous_code=True的解决方法
问题:CSV问答机器人加载文件触发ValueError报错
报错信息
ValueError: This agent relies on access to a python repl tool which can execute arbitrary code. This can be dangerous and requires a specially sandboxed environment to be safely used. Please read the security notice in the doc-string of this function. You must opt-in to use this functionality by setting allow_dangerous_code=True.For general security guidelines, please see: https://python.langchain.com/v0.2/docs/security/
报错栈信息
File "c:\Users\ \langchain-ask-csv\.venv\Lib\site-packages\streamlit\runtime\scriptrunner\script_runner.py", line 589, in _run_script exec(code, module.__dict__) File "C:\Users\ \langchain-ask-csv\main.py", line 46, in <module> main() File "C:\Users\ \langchain-ask-csv\main.py", line 35, in main agent = create_csv_agent( OpenAI(), csv_file, verbose=True) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "c:\Users\langchain-ask-csv\.venv\Lib\site-packages\langchain_experimental\agents\agent_toolkits\csv\base.py", line 66, in create_csv_agent return create_pandas_dataframe_agent(llm, df, **kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "c:\Users\ T\langchain-ask-csv\.venv\Lib\site-packages\langchain_experimental\agents\agent_toolkits\pandas\base.py", line 248, in create_pandas_dataframe_agent raise ValueError(
核心代码片段
def main(): load_dotenv() # Load the OpenAI API key from the environment variable if os.getenv("OPENAI_API_KEY") is None or os.getenv("OPENAI_API_KEY") == "": print("OPENAI_API_KEY is not set") exit(1) else: print("OPENAI_API_KEY is set") st.set_page_config(page_title="Ask your CSV") st.header("Ask your CSV 📈") csv_file = st.file_uploader("Upload a CSV file", type="csv") if csv_file is not None: agent = create_csv_agent( OpenAI(), csv_file, verbose=True) user_question = st.text_input("Ask a question about your CSV: ") if user_question is not None and user_question != "": with st.spinner(text="In progress..."): st.write(agent.run(user_question)) if __name__ == "__main__": main()
问题原因
create_csv_agent底层依赖Python REPL工具,该工具可执行任意代码,存在安全风险- LangChain v0.2及以上版本默认禁用该功能,必须显式声明同意使用才能启用,否则触发此报错
修复方案
在创建create_csv_agent实例时,添加allow_dangerous_code=True参数,明确开启该功能。修改后的核心代码如下:
def main(): load_dotenv() # Load the OpenAI API key from the environment variable if os.getenv("OPENAI_API_KEY") is None or os.getenv("OPENAI_API_KEY") == "": print("OPENAI_API_KEY is not set") exit(1) else: print("OPENAI_API_KEY is set") st.set_page_config(page_title="Ask your CSV") st.header("Ask your CSV 📈") csv_file = st.file_uploader("Upload a CSV file", type="csv") if csv_file is not None: # 添加allow_dangerous_code=True参数 agent = create_csv_agent(OpenAI(), csv_file, verbose=True, allow_dangerous_code=True) user_question = st.text_input("Ask a question about your CSV: ") if user_question is not None and user_question != "": with st.spinner(text="In progress..."): st.write(agent.run(user_question)) if __name__ == "__main__": main()
注意:启用该功能后,建议在安全隔离的环境中运行应用,避免执行恶意代码带来的风险。
内容的提问来源于stack exchange,提问作者Marcelo Rodrigo Nascimento
相关产品推荐
相关产品推荐

