Skip to main content
Glama
Eis4TY

SymPy Sandbox MCP

by Eis4TY

SymPy Sandbox MCP

English | 中文版

A production-focused MCP service that lets agents/LLMs run SymPy safely and efficiently. It combines AST policy checks, runtime resource limits, and prewarmed workers to deliver low-noise, parse-friendly results.

Features

  • Single tool: sympy (input only requires code)

  • Prewarmed worker pool to avoid repeated import sympy

  • Two-layer safety: AST guard + runtime resource limits

  • Compact structured JSON output for low token overhead

  • Standardized error codes for reliable auto-retry workflows

Related MCP server: ReasonForge

Typical Use Cases

  • Symbolic algebra, differentiation, integration, equation solving

  • MCP tool integration for Codex / Cursor / Claude Desktop / custom MCP clients

  • Agent workflows that need controllable failures and clean error signals

Call example:

fastmcp call \
  --command 'python -m sym_mcp.server' \
  --target sympy \
  --input-json '{"code":"import sympy as sp\\nx=sp.Symbol(\"x\")\\nprint(sp.factor(x**2-1))"}'

Client config (python -m, recommended):

{
  "mcpServers": {
    "sympy-sandbox": {
      "command": "python",
      "args": ["-m", "sym_mcp.server"]
    }
  }
}

Client config (installed as sym-mcp):

{
  "mcpServers": {
    "sympy-sandbox": {
      "command": "sym-mcp",
      "args": []
    }
  }
}

Client config (uvx):

{
  "mcpServers": {
    "sympy-sandbox": {
      "command": "uvx",
      "args": ["sym-mcp"]
    }
  }
}

Quick Start

1) Requirements

  • Python 3.11+

  • Linux / macOS (Linux recommended for production)

2) Install (Tsinghua mirror first)

pip install -i https://pypi.tuna.tsinghua.edu.cn/simple -e .
pip install -i https://pypi.tuna.tsinghua.edu.cn/simple -e ".[dev]"

3) Run server (stdio)

python -m sym_mcp.server

4) Verify tool

fastmcp list --command 'python -m sym_mcp.server'

Tool Contract

Tool name

  • sympy

Input

  • code: str

Notes:

  • You must print() final outputs.

  • If nothing is printed, out may be empty.

Output (always compact JSON string)

Success:

{"out":"x**2/2"}

Failure:

{"code":"E_RUNTIME","line":3,"err":"ZeroDivisionError: division by zero","hint":"Runtime error. Check variable types, division-by-zero, or undefined names near the reported line."}

Field definitions:

  • out: stdout text on success

  • code: error code

  • line: user code error line, or null

  • err: compact error message (traceback noise removed)

  • hint: fix hint (based on configured hint level)

  • If out / err / hint is too long, it will be truncated with ...[truncated]

Error Codes

  • E_AST_BLOCK: blocked by AST safety policy

  • E_SYNTAX: syntax error

  • E_TIMEOUT: timeout

  • E_MEMORY: memory limit triggered

  • E_RUNTIME: general runtime error

  • E_WORKER: worker communication/state failure

  • E_INTERNAL: internal server error

  1. Use math-only Python code.

  2. Only import sympy or math.

  3. Always print() final answers.

  4. For multiple outputs, use multiple print() lines.

  5. On failure, patch minimally near line and retry.

  6. For E_TIMEOUT, reduce scale first; for E_MEMORY, reduce object size/dimension; for E_AST_BLOCK, remove unsafe statements.

Example:

import sympy as sp
x = sp.Symbol("x")
expr = (x + 1)**5
print(sp.expand(expr))

Security Model

Before execution (AST policy)

  • Only sympy / math imports are allowed

  • Dangerous capabilities are blocked (eval, exec, open, __import__, etc.)

  • Dunder attribute traversal is blocked (e.g. __class__)

During execution (OS resource limits)

  • Per-task CPU time limit + timeout kill

  • Per-worker memory limit via setrlimit

  • Worker auto-rebuild on failure to keep server healthy

Architecture

  • src/sym_mcp/server.py: MCP entrypoint and tool registration

  • src/sym_mcp/security/ast_guard.py: AST validation

  • src/sym_mcp/executor/worker_main.py: worker loop

  • src/sym_mcp/executor/pool.py: async prewarmed process pool

  • src/sym_mcp/executor/sandbox.py: restricted execution and stdout capture

  • src/sym_mcp/errors/parser.py: error normalization and code mapping

  • src/sym_mcp/config.py: runtime configuration

Configuration (Environment Variables)

  • SYMMCP_POOL_SIZE: worker pool size, default 10

  • SYMMCP_EXEC_TIMEOUT_SEC: per execution timeout (sec), default 3

  • SYMMCP_MEMORY_LIMIT_MB: memory cap per worker (MB), default 150

  • SYMMCP_QUEUE_WAIT_SEC: queue wait timeout (sec), default 2

  • SYMMCP_LOG_LEVEL: log level, default INFO

  • SYMMCP_MAX_OUTPUT_CHARS: output truncation threshold, default 1200

  • SYMMCP_HINT_LEVEL: hint level (none/short/medium), default medium

FAQ

Why is out empty?

Most likely the code does not print() the final result.

Why return compact JSON string?

It is easier for agents to parse reliably and reduces token cost.

Is memory limiting always stable on macOS?

setrlimit behavior differs by OS. Linux is preferred for production.

Does it support HTTP/SSE?

Current primary delivery is stdio. HTTP/SSE can be added later via FastMCP transport extensions.

Known Limits

  • This is restricted Python execution, not VM/container-grade isolation

  • Memory limit behavior is OS-dependent

  • Output is truncated at threshold, with ...[truncated] suffix

Development

Run tests

PYTHONPATH=src pytest -q

Benchmark

PYTHONPATH=src python scripts/benchmark.py --concurrency 100 --total 500

Contributing

  • Run PYTHONPATH=src pytest -q before submitting PRs

  • When adding new capabilities, update:

    • error code docs

    • README examples

    • related unit/integration tests

  • Publishing process: PUBLISHING.md

Available Tools

1 tool
sympyA

SymPy sandbox tool: execute Python/SymPy math code.

Safety boundaries:

  • Only sympy/math imports and calls are allowed.

  • System calls, file I/O, network access, and dynamic execution are blocked.

Input rules:

  • Single argument: code (str).

  • You must print() the final answer; otherwise out may be empty.

  • Use multiple print() lines for multiple outputs.

Recommended workflow:

  1. Define symbols and assumptions.

  2. Derive/solve step by step.

  3. Simplify intermediate expressions (simplify/factor/expand).

  4. Print final results.

Retry guidance:

  • E_AST_BLOCK: remove unsafe statements and keep pure math code only.

  • E_TIMEOUT: reduce problem size, split steps, simplify before solving.

  • E_MEMORY: reduce dimensions or avoid constructing huge objects at once.

ParametersJSON Schema
NameRequiredDescriptionDefault
codeYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It thoroughly describes safety boundaries (blocked system calls, file I/O, network access), execution constraints (must print() results), and error conditions with retry strategies, offering rich behavioral context beyond basic functionality.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured with clear sections (safety boundaries, input rules, workflow, retry guidance) and uses bullet points for readability. It is appropriately sized for the tool's complexity, though some sentences could be slightly more concise (e.g., the workflow steps are detailed but not overly verbose).

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (sandboxed code execution), lack of annotations, and low schema coverage, the description is highly complete. It covers purpose, usage, safety, parameters, workflow, and error handling. The presence of an output schema means return values need not be explained, and the description addresses all other critical aspects thoroughly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema has 0% description coverage for its single parameter 'code', but the description compensates fully by explaining that 'code' is a string containing Python/SymPy math code, detailing input rules (single argument, must print()), and providing workflow examples. It adds significant meaning beyond the bare schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose as executing Python/SymPy math code in a sandbox environment. It specifies the exact functionality (execute code), the domain (math/SymPy), and the context (sandbox with safety boundaries), making it highly specific and unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit guidance on when and how to use the tool, including a recommended workflow (steps 1-4), input rules (single code argument, use print()), and retry guidance for specific errors (E_AST_BLOCK, E_TIMEOUT, E_MEMORY). It comprehensively covers usage scenarios and error handling.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev0.1.0
    • First observedsympy

TDQS

A4.5/5.0
Disambiguation5/5

With only one tool, there is no possibility of ambiguity or overlap between tools. The single tool 'sympy' has a clear and distinct purpose: executing Python/SymPy math code within a sandboxed environment.

Naming Consistency5/5

Since there is only one tool, naming consistency is inherently perfect. The tool name 'sympy' is straightforward and matches the server's purpose, with no other tools to compare against for patterns.

Tool Count2/5

A single tool is too few for the apparent scope of a SymPy sandbox, which could benefit from more granular operations like simplify, solve, or differentiate. This minimal set may force agents to bundle multiple steps into one call, reducing flexibility and increasing error risk.

Completeness2/5

The tool surface is severely incomplete for mathematical computation. While the single tool can execute arbitrary SymPy code, it lacks dedicated tools for common operations (e.g., simplification, solving equations, calculus), making it harder for agents to reliably perform structured tasks without manual coding in each call.

Maintenance

ActivityInactive
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides a suite of deterministic math tools powered by SymPy to handle algebra, calculus, linear algebra, and statistics via the Model Context Protocol. It enables smaller language models to delegate complex computations to a verified symbolic backend for accurate and reliable results.
    Apache 2.0
  • A
    license
    B
    quality
    A
    maintenance
    Enables deterministic verification for AI assistants by executing Python code that uses symbolic engines like SymPy and Z3 for math, logic, and code analysis.
    2
    Apache 2.0

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Eis4TY/Sym-MCP'

If you have feedback or need assistance with the MCP directory API, please join our Discord server