Atlas / MCP servers / bazinga012 / Code Executor

Code ExecutorCAUTION

mcp/bazinga012/code-executor

The MCP Code Executor is an MCP server that allows LLMs to execute Python code within a specified Conda environment.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
9 4r · 5w · 0d
Transport
stdio
License
MIT
Stars
212
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@bazinga012/mcpcodeexecutor)

The MCP Code Executor is an MCP server that allows LLMs to execute Python code within a specified Python environment. This enables LLMs to run code with access to libraries and dependencies defined in the environment. It also supports incremental code generation for handling large code blocks that may exceed token limits.

Features

  • Execute Python code from LLM prompts
  • Support for incremental code generation to overcome token limitations
  • Run code within a specified environment (Conda, virtualenv, or UV virtualenv)
  • Install dependencies when needed
  • Check if packages are already installed
  • Dynamically configure the environment at runtime
  • Configurable code storage directory

Prerequisites

  • Node.js installed
  • One of the following:
  • Conda installed with desired Conda environment created
  • Python virtualenv
  • UV virtualenv

Setup

  1. Clone this repository:
git clone https://github.com/bazinga012/mcp_code_executor.git
  1. Navigate to the project directory:
cd mcp_code_executor
  1. Install the Node.js dependencies:
npm install
  1. Build the project:
npm run build

Configuration

To configure the MCP Code Executor server, add the following to your MCP servers configuration file:

Using Node.js

{
"mcpServers": {
"mcp-code-executor": {
"command": "node",
"args": [
"/path/to/mcp_code_executor/build/index.js" 
],
"env": {
"CODE_STORAGE_DIR": "/path/to/code/storage",
"ENV_TYPE": "conda",
"CONDA_ENV_NAME": "your-conda-env"
}
}
}
}

Using Docker

{
"mcpServers": {
"mcp
Read from source at commit bad2d021eaacOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add code_execution_server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "code_execution_server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (9)

4 read · 5 write · 0 destructive.

ToolRiskDescription
append_to_code_filewriteAppend content to an existing Python code file. Use this to add more code to a file created with initialize_code_file, allowing you to build up larger code bases in parts.
check_installed_packagesreadCheck if packages are installed in the ${ENV_CONFIG.type} environment
configure_environmentreadChange the environment configuration settings
execute_codewriteExecute Python code in the ${ENV_CONFIG.type} environment. For short code snippets only. For longer code, use initialize_code_file and append_to_code_file instead.
execute_code_filewriteExecute an existing Python file. Use this as the final step after building up code with initialize_code_file and append_to_code_file.
get_environment_configreadGet the current environment configuration
initialize_code_filewriteCreate a new Python file with initial content. Use this as the first step for longer code that may exceed token limits. Follow with append_to_code_file for additional code.
install_dependencieswriteInstall Python dependencies in the ${ENV_CONFIG.type} environment
read_code_filereadRead the content of an existing Python code file. Use this to verify the current state of a file before appending more content or executing it.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
build/index.js:384
module = importlib.import_module(package)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/index.ts:431
module = importlib.import_module(package)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
mcp-framework, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha bad2d021eaacfull audit observations/trust-audit/mcp-server/bazinga012__code-executor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06bad2d021eaacCAUTIONB89first audit
06

Questions

What is the Code Executor MCP server?

The MCP Code Executor is an MCP server that allows LLMs to execute Python code within a specified Conda environment.

What tools does Code Executor expose?

9 in total: 4 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Code Executor safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Code Executor need?

No credential environment variables were found in its source, so it appears to need none.

How does Code Executor run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as code_execution_server at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (bad2d021eaac), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement