Atlas / MCP servers / maxim-saplin / Safe Local Python Executor

Safe Local Python ExecutorSAFE

mcp/maxim-saplin/safe-local-python-executor

Stdio MCP Server wrapping custom Python runtime (LocalPythonExecutor) from Hugging Faces' `smolagents` framework. The runtime combines the ease of setup (compared to docker, VM, cloud runtimes) while providing safeguards and limiting operations/imports that are allowed inside the runtime.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
MIT
Stars
48
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server (stdio transport) that wraps Hugging Face's `LocalPythonExecutor` (from the `smolagents` framework). It is a custom Python runtime that provides basic isolation/security when running Python code generated by LLMs locally. It does not require Docker or VM. This package allows to expose the Python executor via MCP (Model Context Protocol) as a tool for LLM apps like Claude Desktop, Cursor or any other MCP compatible client. In case of Claude Desktop this tool is an easy way to add a missing Code Interpreter (available as a plugin in ChatGPT for quite a while already).

Features

  • Exposes run_python tool
  • Safer execution of Python code compared to direct use of Python eva()l
  • Ran via uv in Python venv
  • No file I/O ops are allowed
  • Restricted list of imports
  • collections
  • datetime
  • itertools
  • math
  • queue
  • random
  • re
  • stat
  • statistics
  • time
  • unicodedata

Security

Be careful with execution of code produced by LLM on your machine, stay away from MCP servers that run Python via command line or using eval(). The safest option is using a VM or a docker container, though it requires some effort to set-up, consumes resources/slower. There're 3rd party servcices providing Python runtime, though they require registration, API keys etc.

LocalPythonExecutor provides a good balance between direct use of local Python environment (which is easier to set-up) AND remote execution in Dokcer container or a VM/3rd party service (which is safe). Hugginng Face team has invested time into creating a quick and safe option to run LLM generated code used by their code agents. This MCP server builds upon it:

To add
Read from source at commit 77cd360e4c99OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp_safe_local_python_executor -- uvx mcp_safe_local_python_executor
claude-desktop
{
  "mcpServers": {
    "mcp_safe_local_python_executor": {
      "command": "uvx",
      "args": [
        "mcp_safe_local_python_executor"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
run_pythonwriteExecute Python code in a secure sandbox environment.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 77cd360e4c99full audit observations/trust-audit/mcp-server/maxim-saplin__safe-local-python-executor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0877cd360e4c99SAFEB89first audit
06

Questions

What is the Safe Local Python Executor MCP server?

Stdio MCP Server wrapping custom Python runtime (LocalPythonExecutor) from Hugging Faces' `smolagents` framework. The runtime combines the ease of setup (compared to docker, VM, cloud runtimes) while providing safeguards and limiting operations/imports that are allowed inside the runtime.

What tools does Safe Local Python Executor expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Safe Local Python Executor safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Safe Local Python Executor need?

No credential environment variables were found in its source, so it appears to need none.

How does Safe Local Python Executor run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp_safe_local_python_executor.

How current is this page?

The grade is for one exact copy of the source (77cd360e4c99), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement