AI agents and chatbots increasingly run Python code interpreters, often for data analysis, that can be abused by attackers. We’ll show how prompt-to-RCE, credentials abuse, & C2 payloads work in these sandboxes, including a real AWS AgentCore breakout & hardening against code interpreter exploits.