Atlas / MCP servers / gradion-ai / Ipybox

IpyboxSAFE

mcp/gradion-ai/ipybox

Unified execution environment for Python code, shell commands, and programmatic MCP tool calls.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
75
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

mcp-name: io.github.gradion-ai/ipybox

ipybox is a unified execution environment for Python code, shell commands, and programmatic MCP tool calls.

Overview

ipybox executes code blocks in a stateful IPython kernel. A code block can contain any combination of Python code, shell commands, and programmatic MCP tool calls. Kernels can be sandboxed with sandbox-runtime, enforcing filesystem and network restrictions at OS level.

It generates Python APIs for MCP server tools via mcpygen, and supports application-level approval of individual tool calls and shell commands during code execution. ipybox runs locally on your computer, enabling protected access to your local data and tools.

[!NOTE] Next generation ipybox This is the next generation of ipybox, a complete rewrite. Older versions are maintained on the [0.6.x branch](https://g
Read from source at commit 5f460cfb3a07OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add ipybox -- uvx ipybox==0.0.0
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (9)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.worktreeinclude
.worktreeinclude
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
docs/CLAUDE.md
docs/CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
tests/CLAUDE.md
tests/CLAUDE.md
Why it matters. link not followed
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
ipybox/kernel_mgr/client.py:318
img_bytes = b64decode(msg_data["image/png"])
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/sandbox.md:59
The server itself is configured with permissions to access all files in the current directory (`"."`), but the sandbox additionally blocks read access to `.env`. The sandbox also allows access to `reg
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
docs/sandbox.md:47
stdio MCP servers like the [filesystem MCP server](https://github.com/modelcontextprotocol/servers/tree/main/src/filesystem) can be configured to run in a sandbox using `srt` as command:
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 5f460cfb3a07full audit observations/trust-audit/mcp-server/gradion-ai__ipybox.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-075f460cfb3a07SAFEB89first audit
05

Questions

What is the Ipybox MCP server?

Unified execution environment for Python code, shell commands, and programmatic MCP tool calls.

Is Ipybox safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ipybox need?

No credential environment variables were found in its source, so it appears to need none.

How does Ipybox run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ipybox.

How current is this page?

The grade is for one exact copy of the source (5f460cfb3a07), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement