Mcp-Client-XSAFE
Python MCP client + server example
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project demonstrates a simple client-server implementation using the Model Context Protocol (MCP), which is a standardized way to connect large language models with tools and data.
Overview
This example shows how to:
- Create an MCP server with custom tools
- Connect to the server using an MCP client
- Call tools and get responses from the server
Tutorial Video
[](https://youtu.be/oq3dkNm51qc)
Click the image above to watch a tutorial on MCP implementation.
Project Structure
. ├── pyproject.toml ├── README.md ├── src │ ├── client │ │ └── mcp_client.py # MCP client implementation │ └── server │ └── example_server.py # MCP server with tools └── uv.lock
Server Implementation
The server exposes two tools:
calculate_bmi- A simple calculator that computes Body Mass Indexfetch_weather- An async tool that retrieves weather data from an external API
Client Implementation
The client connects to the server via stdio, initializes a session, and calls the server's tools.
Getting Started
Prerequisites
- Python 3.9+
- uv (Python package manager)
Installation
# Install dependencies uv install -e .
Running the Example
- Start the client (which will automatically start the server):
uv run src/client/mcp_client.py
Usage
The client will:
- Connect to the server
- List available tools
- Call the BMI calculator with sample data
- Call the weather tool with sample coordinates
Example Response
Available tools: meta=None nextCursor=None tools=[...]
BMI calculation result: 22.857142857142858
Weather data: {"current_weather":{"temperature":14.2,"windspeed":12.6, ...}}Test with MCP Inspector
( run command below and then visit http://localhost:5173 )
❯ mcp dev src/server/example_server.py Starting MCP inspector... Proxy server listening on port 3000 🔍
9e77b915f4d3OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-client-x --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx mcp-client-x{
"mcpServers": {
"mcp-client-x": {
"command": "uvx",
"args": [
"mcp-client-x"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
calculate_bmi | read | Calculate BMI given weight in kg and height in meters |
fetch_weather | read | Fetch current weather for a location using latitude and longitude |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Gates applied: no_behavioural_pass, no_license.
9e77b915f4d3full audit observations/trust-audit/mcp-server/rggh__mcp-client-x.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 9e77b915f4d3 | SAFE | B | 89 | first audit |
Questions
What is the Mcp-Client-X MCP server?
Python MCP client + server example
What tools does Mcp-Client-X expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp-Client-X safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mcp-Client-X need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9e77b915f4d3), read on 2026-10-09. The repository is watched and re-audited when it changes.