Python LocalBLOCK
MCP Server to run python code locally
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP Server that provides an interactive Python REPL (Read-Eval-Print Loop) environment.
Components
Resources
The server provides access to REPL session history:
- Custom
repl://URI scheme for accessing session history - Each session's history can be viewed as a text/plain resource
- History shows input code and corresponding output for each execution
Tools
The server implements one tool:
python_repl: Executes Python code in a persistent session- Takes
code(Python code to execute) andsession_idas required arguments - Maintains separate state for each session
- Supports both expressions and statements
- Captures and returns stdout/stderr output
Configuration
Install
Claude Desktop
On MacOS: ~/Library/Application\ Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
Development/Unpublished Servers Configuration
"mcpServers": {
"python_local": {
"command": "uv",
"args": [
"--directory",
"/path/to/python_local",
"run",
"python_local"
]
}
}Published Servers Configuration
"mcpServers": {
"python_local": {
"command": "uvx",
"args": [
"python_local"
]
}
}Development
Building and Publishing
To prepare the package for distribution:
- Sync dependencies and update lockfile:
uv sync
- Build package distributions:
uv build
This will create source and wheel distributions in the dist/ directory.
- Publish to PyPI:
uv publish
Note: You'll need to set PyPI credentials via environment variables or command flags:
- Token:
--tokenorUV_PUBLISH_TOKEN - Or username/password:
--username/UV_PUBLISH_USERNAMEand--password/UV_PUBLISH_PASSWORD
Debugging
Since MCP servers r
18f0a2a688d3OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add python-local -- uvx python-local
{
"mcpServers": {
"python-local": {
"command": "uvx",
"args": [
"python-local"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
python_repl | read | Interactive Python REPL that maintains session state. NOTE THE USER DOES NOT SEE THE STDOUT/STDERR OUTPUT, MAKE SURE TO FORMAT/SUMMARIZEc IT APPROPRIATELY IN YOUR RESPONSE TO THE USER |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
result = eval(code, self.locals)
exec(code, self.locals)
Gates applied: no_behavioural_pass, no_license.
18f0a2a688d3full audit observations/trust-audit/mcp-server/alec2435__python-local.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 18f0a2a688d3 | BLOCK | D | 69 | first audit |
Questions
What is the Python Local MCP server?
MCP Server to run python code locally
What tools does Python Local expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Python Local safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Python Local need?
No credential environment variables were found in its source, so it appears to need none.
How does Python Local run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as python-local.
How current is this page?
The grade is for one exact copy of the source (18f0a2a688d3), read on 2026-10-08. The repository is watched and re-audited when it changes.