Atlas / MCP servers / datalayer / jupyter-mcp-server

jupyter-mcp-serverBLOCK

mcp/datalayer/jupyter-mcp-server

🪐 🔧 Model Context Protocol (MCP) Server for Jupyter.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 1r · 1w · 0d
Transport
stdio · streamable-http
License
BSD-3-Clause
Stars
1,286
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/sponsors/datalayer)

An [MCP](https://modelcontextprotocol.io) server developed for AI to connect and manage [Jupyter](https://jupyter.org) Notebooks in real-time — and scale your [Code Sandbox](https://jupyter-mcp-server.datalayer.tech/code-sandboxes) from local to the cloud (Datalayer, Kaggle, Google Colab, Modal, Daytona, E2B, CoreWeave, Cloudflare...)

Developed by [Datalayer](https://datalayer.ai) - Join our [Discord](https://discord.gg/YQFwvmSSuR)

[](https://pypi.org/project/jupyter-mcp-server) [](https://pepy.tech/project/jupyter-mcp-server) [](https://hub.docker.com/r/datalayer/jupyter-mcp-server) [](https://opensource.org/licenses/BSD-3-Clause)

[](https://datalayer.ai)

📖 Documentation · 🔧 Tools

Read from source at commit f36b91356ee4OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add jupyter-mcp-server-docs --env MCP_TOKEN=${MCP_TOKEN} -- npx -y @datalayer/[email protected]
claude-desktop
{
  "mcpServers": {
    "jupyter-mcp-server-docs": {
      "command": "npx",
      "args": [
        "-y",
        "@datalayer/[email protected]"
      ],
      "env": {
        "MCP_TOKEN": "${MCP_TOKEN}"
      }
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
read_cellreadRead a cell.
touch_the_notebookwritePublish, exactly as a writing tool
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (10 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
jupyter_mcp_server/cli/commands/connect.py:109
typer.Option("--insecure-mcp-noauth", envvar="INSECURE_MCP_NOAUTH"),
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
jupyter_mcp_server/cli/commands/serve.py:245
help="Token for authenticating MCP clients (Bearer scheme). Required for streamable-http unless --insecure-mcp-noauth is set.",
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
jupyter_mcp_server/notifications.py:236
module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
jupyter_mcp_server/resources.py:103
module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
jupyter_mcp_server/tasks.py:313
module = importlib.import_module(module_name)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.licenserc.yaml
.licenserc.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
extensions/mcpb/.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
.github/workflows/test.yml:37
importlib.import_module(mod.name)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_documented_features.py:471
exec("import ast\n" + text[start:end], namespace)  # noqa: S102
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_tools.py:420
expected_result = eval(code_content)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_tools.py:425
expected_result = eval(code_content)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/src/components/HomepageFeatures.js:15
Svg: require('../../static/img/feature_1.svg').default,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/src/components/HomepageFeatures.js:25
Svg: require('../../static/img/feature_2.svg').default,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/src/components/HomepageFeatures.js:34
Svg: require('../../static/img/feature_3.svg').default,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/src/components/HomepageProducts.js:15
Svg: require('../../static/img/product_1.svg').default,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/src/components/HomepageProducts.js:24
Svg: require('../../static/img/product_2.svg').default,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/docs/mcp-transports/streamable-http-extension/index.mdx:65
This starts JupyterLab at [http://127.0.0.1:4040](http://127.0.0.1:4040) with the MCP server integrated.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/docs/mcp-transports/streamable-http-extension/index.mdx:77
claude mcp add jupyter --transport http http://127.0.0.1:4040/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/docs/mcp-transports/streamable-http-extension/index.mdx:90
"http://127.0.0.1:4040/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/docs/mcp-transports/streamable-http/index.mdx:199
claude mcp add jupyter --transport http http://127.0.0.1:4040/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/docs/mcp-transports/streamable-http/index.mdx:212
"http://127.0.0.1:4040/mcp",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
docs/sourcey/build_pages.mjs:241
`- \`streamable-http\` — served by uvicorn on \`--port\`; requires \`--mcp-token\` unless \`--insecure-mcp-noauth\` is passed.`,
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
examples/cli/Makefile:37
@echo "  start-noauth - Start everything with --insecure-mcp-noauth (local dev only)"
Why it matters. certificate verification is disabled
Fix. leave verification on

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha f36b91356ee4full audit observations/trust-audit/mcp-server/datalayer__jupyter-mcp-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-25f36b91356ee4BLOCKD69first audit
06

Questions

What is the jupyter-mcp-server MCP server?

🪐 🔧 Model Context Protocol (MCP) Server for Jupyter.

What tools does jupyter-mcp-server expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is jupyter-mcp-server safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does jupyter-mcp-server need?

It reads MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does jupyter-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @datalayer/jupyter-mcp-server-docs at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (f36b91356ee4), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement