Atlas / MCP servers / aberemia24 / Code Executor

Code ExecutorBLOCK

mcp/aberemia24/code-executor-1
Verdict
BLOCK
Grade
F
Trust score
38 /100
Exposed tools
44 42r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
128
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Stop hitting the 2-3 MCP server wall. One MCP to orchestrate them all - 98% token savings, unlimited tool access.

[](https://www.npmjs.com/package/code-executor-mcp) [](https://hub.docker.com/r/aberemia24/code-executor-mcp) [](https://opensource.org/licenses/MIT)

Why Use Code Executor MCP?

  • 98% Token Reduction - 141k → 1.6k tokens (load 1 executor vs 50+ tools)
  • Sandboxed Security - Isolated Deno/Python execution, no internet by default, audit logging
  • Type-Safe Wrappers - Auto-generated TypeScript/Python SDK with full IntelliSense
  • Progressive Disclosure - Tools loaded on-demand inside sandbox, not upfront in context
  • Zero Config Setup - Wizard auto-detects existing MCP servers from Claude Code/Cursor
  • Production Ready - 606 tests, 95%+ coverage, Docker support, rate limiting

The Problem

You can't use more than 2-3 MCP servers before context exhaustion kills you.

You're forced to choose: filesystem OR browser OR git OR AI tools. Never all of them.

The Solution

Disable all MCPs. Enable only code-executor-mcp.

# Before: 47 tools, 141k tokens
mcp__filesystem__read_file
mcp__filesystem__write_file
mcp__git__commit
mcp__browser__navigate
... 43 more tools

# After: 2 tools, 1.6k tokens (98% reduction)
run-typescript-code
run-python-code

Inside the sandbox, access ANY MCP tool on-demand:

// Claude writes this automatically
const file = await callMCPTool('mcp__filesystem__read_file', { path: '/
Read from source at commit d137981930abOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add code-executor-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "code-executor-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
        "AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
        "AWS_SESSION_TOKEN": "${AWS_SESSION_TOKEN}"
      }
    }
  }
}
03

Exposed tools (44)

42 read · 2 write · 0 destructive.

ToolRiskDescription
CursorreadAI-first code editor
OpenCodereadOpen-source AI code completion
TestreadTest
WindsurfreadAI-powered development assistant
brokenreadBroken server
complex_toolreadComplex tool
executePythonread
executeTypescriptread
filesystemreadFile system operations
healthread
legacy-toolreadLegacy tool without outputSchema
mcp-onereadFirst MCP
mcp-tworeadSecond MCP
mcp__filesystem__read_filereadRead file contents
mcp__filesystem__write_filewriteWrite file contents
mcp__network__fetch_urlreadFetch content from a URL
mcp__server1__code_reviewreadReview code for quality
mcp__server1__file_readreadRead file contents
mcp__server1__test_runnerwriteRun automated tests
mcp__server1__tool1readCached schema
mcp__server1__tool2readTest tool 2
mcp__server2__data_analysisreadAnalyze data patterns
mcp__test__allowed_toolreadTest tool
mcp__test__some_long_namereadTest
mcp__zen__codereviewread...
my-server-123readServer with hyphens
my_server_v2readServer with underscores
safe-serverread{{process.exit()}} <script>alert(
safe_toolreadSafe tool
testread{{#with process}}{{exit}}{{/with}}
test-serverreadTest MCP server
test-server-2readTest MCP server
test-toolreadTest tool
test-tool-1readTest tool 1
test-tool-2readTest tool 2
testLongNamereadTest
testTool1readTest tool for file operations
testTool2readTest tool for network operations
test_toolreadA test tool
test_tool_v2readTest tool v2 (updated)
tool1readTool 1
tool2readTool 2
tool3readTool 3
测试包readТестовый пакет
04

Trust audit

BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (7 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/validation/security-validator.ts:61
/pickle\.loads/i,                          // pickle.loads() - deserialization RCE
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/cli/mcp-discovery.ts:243
exec(`${checkCommand} ${server.command}`, (error, stdout, _stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/executors/python-executor.ts:61
exec(open('${userCodeFile}').read())
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/validation/security-validator.ts:43
/\beval\s*\(/i,                            // eval( with whitespace
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/validation/security-validator.ts:59
/\bexec\s*\(/i,                            // exec() - execute arbitrary code
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/validation/security-validator.ts:142
`(169.254.169.254, metadata.google.internal).`
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
CHANGELOG.md:494
- Type safety violation: Unsafe casts bypass compiler safety checks
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
CHANGELOG.md:759
- Type safety violation: Unsafe casts bypass compiler safety checks
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/verify-progressive-disclosure.ts:98
console.log(`Token Usage: ~${totalTokens} tokens (Target: ~1.6k) - ${totalTokens < 2000 ? '✅ PASS' : '⚠️  REVIEW'}`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.example.json
.mcp.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.test-debug-wrapper.mjs
.test-debug-wrapper.mjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/security/pattern-bypass.test.ts:161
expectBlocked('pickle.loads(data)');
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/security.test.ts:158
const code = 'new Function("return 1")()';
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/cli/schedulers/systemd-scheduler.test.ts:289
expect(() => new SystemdScheduler('../../.ssh/authorized_keys')).toThrow(
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security/symlink-attacks.test.ts:357
const symlinkPath = path.join(allowedDir, 'id_rsa');
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/discovery-request-handler.ts:32
import type { SchemaCache } from '../../validation/schema-cache.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/discovery-request-handler.ts:33
import type { RateLimiter } from '../../security/rate-limiter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/discovery-request-handler.ts:34
import type { ToolSchema } from '../../types/discovery.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/discovery-request-handler.ts:35
import { normalizeError } from '../../utils/utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/health-check-handler.ts:24
import type { SchemaCache } from '../../validation/schema-cache.js';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
SECURITY.md:87
- Cloud metadata endpoints (`169.254.169.254`)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
SECURITY.md:106
- `169.254.169.254`, `metadata.google.internal` (cloud metadata)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
race-condition-test.ts:247
{ url: 'http://[::ffff:169.254.169.254]', desc: 'IPv4-mapped metadata service' },
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/network-security.test.ts:42
const hosts = ['169.254.169.254'];
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d137981930abfull audit observations/trust-audit/mcp-server/aberemia24__code-executor-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d137981930abBLOCKF38first audit
06

Questions

What tools does Code Executor expose?

44 in total: 42 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Code Executor safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (38/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Code Executor need?

It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, CODE_EXECUTOR_MAX_SAMPLING_TOKENS, GEMINI_API_KEY, GROK_API_KEY, OPENAI_API_KEY and PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Code Executor run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as code-executor-mcp at 1.0.5.

How current is this page?

The grade is for one exact copy of the source (d137981930ab), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement