Code ExecutorBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Stop hitting the 2-3 MCP server wall. One MCP to orchestrate them all - 98% token savings, unlimited tool access.
[](https://www.npmjs.com/package/code-executor-mcp) [](https://hub.docker.com/r/aberemia24/code-executor-mcp) [](https://opensource.org/licenses/MIT)
Why Use Code Executor MCP?
- 98% Token Reduction - 141k → 1.6k tokens (load 1 executor vs 50+ tools)
- Sandboxed Security - Isolated Deno/Python execution, no internet by default, audit logging
- Type-Safe Wrappers - Auto-generated TypeScript/Python SDK with full IntelliSense
- Progressive Disclosure - Tools loaded on-demand inside sandbox, not upfront in context
- Zero Config Setup - Wizard auto-detects existing MCP servers from Claude Code/Cursor
- Production Ready - 606 tests, 95%+ coverage, Docker support, rate limiting
The Problem
You can't use more than 2-3 MCP servers before context exhaustion kills you.
- Research confirms: Tool accuracy drops significantly after 2-3 servers
- 6,490+ MCP servers available, but you can only use 2-3
- 47 tools = 141k tokens consumed before you write a single word
You're forced to choose: filesystem OR browser OR git OR AI tools. Never all of them.
The Solution
Disable all MCPs. Enable only code-executor-mcp.
# Before: 47 tools, 141k tokens mcp__filesystem__read_file mcp__filesystem__write_file mcp__git__commit mcp__browser__navigate ... 43 more tools # After: 2 tools, 1.6k tokens (98% reduction) run-typescript-code run-python-code
Inside the sandbox, access ANY MCP tool on-demand:
// Claude writes this automatically
const file = await callMCPTool('mcp__filesystem__read_file', { path: '/d137981930abOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add code-executor-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"code-executor-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
"AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
"AWS_SESSION_TOKEN": "${AWS_SESSION_TOKEN}"
}
}
}
}Exposed tools (44)
42 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Cursor | read | AI-first code editor |
OpenCode | read | Open-source AI code completion |
Test | read | Test |
Windsurf | read | AI-powered development assistant |
broken | read | Broken server |
complex_tool | read | Complex tool |
executePython | read | |
executeTypescript | read | |
filesystem | read | File system operations |
health | read | |
legacy-tool | read | Legacy tool without outputSchema |
mcp-one | read | First MCP |
mcp-two | read | Second MCP |
mcp__filesystem__read_file | read | Read file contents |
mcp__filesystem__write_file | write | Write file contents |
mcp__network__fetch_url | read | Fetch content from a URL |
mcp__server1__code_review | read | Review code for quality |
mcp__server1__file_read | read | Read file contents |
mcp__server1__test_runner | write | Run automated tests |
mcp__server1__tool1 | read | Cached schema |
mcp__server1__tool2 | read | Test tool 2 |
mcp__server2__data_analysis | read | Analyze data patterns |
mcp__test__allowed_tool | read | Test tool |
mcp__test__some_long_name | read | Test |
mcp__zen__codereview | read | ... |
my-server-123 | read | Server with hyphens |
my_server_v2 | read | Server with underscores |
safe-server | read | {{process.exit()}} <script>alert( |
safe_tool | read | Safe tool |
test | read | {{#with process}}{{exit}}{{/with}} |
test-server | read | Test MCP server |
test-server-2 | read | Test MCP server |
test-tool | read | Test tool |
test-tool-1 | read | Test tool 1 |
test-tool-2 | read | Test tool 2 |
testLongName | read | Test |
testTool1 | read | Test tool for file operations |
testTool2 | read | Test tool for network operations |
test_tool | read | A test tool |
test_tool_v2 | read | Test tool v2 (updated) |
tool1 | read | Tool 1 |
tool2 | read | Tool 2 |
tool3 | read | Tool 3 |
测试包 | read | Тестовый пакет |
Trust audit
BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
/pickle\.loads/i, // pickle.loads() - deserialization RCE
exec(`${checkCommand} ${server.command}`, (error, stdout, _stderr) => {exec(open('${userCodeFile}').read())/\beval\s*\(/i, // eval( with whitespace
/\bexec\s*\(/i, // exec() - execute arbitrary code
`(169.254.169.254, metadata.google.internal).`
- Type safety violation: Unsafe casts bypass compiler safety checks
- Type safety violation: Unsafe casts bypass compiler safety checks
console.log(`Token Usage: ~${totalTokens} tokens (Target: ~1.6k) - ${totalTokens < 2000 ? '✅ PASS' : '⚠️ REVIEW'}`);.eslintignore
.mcp.example.json
.test-debug-wrapper.mjs
expectBlocked('pickle.loads(data)');const code = 'new Function("return 1")()';expect(() => new SystemdScheduler('../../.ssh/authorized_keys')).toThrow(const symlinkPath = path.join(allowedDir, 'id_rsa');
import type { SchemaCache } from '../../validation/schema-cache.js';import type { RateLimiter } from '../../security/rate-limiter.js';import type { ToolSchema } from '../../types/discovery.js';import { normalizeError } from '../../utils/utils.js';import type { SchemaCache } from '../../validation/schema-cache.js';- Cloud metadata endpoints (`169.254.169.254`)
- `169.254.169.254`, `metadata.google.internal` (cloud metadata)
{ url: 'http://[::ffff:169.254.169.254]', desc: 'IPv4-mapped metadata service' },const hosts = ['169.254.169.254'];
Gates applied: instruction_override, no_behavioural_pass.
d137981930abfull audit observations/trust-audit/mcp-server/aberemia24__code-executor-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d137981930ab | BLOCK | F | 38 | first audit |
Questions
What tools does Code Executor expose?
44 in total: 42 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Code Executor safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (38/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Code Executor need?
It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, CODE_EXECUTOR_MAX_SAMPLING_TOKENS, GEMINI_API_KEY, GROK_API_KEY, OPENAI_API_KEY and PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Code Executor run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as code-executor-mcp at 1.0.5.
How current is this page?
The grade is for one exact copy of the source (d137981930ab), read on 2026-10-07. The repository is watched and re-audited when it changes.