venv-manager
venv-manager
One Python environment control layer for developers and every AI coding agent.
Written in Go. One static binary, no runtime deps beyond python3 (or uv, if available).

The GIF above is real: venv-manager watch app.py --venv X monitors a file, scans its imports with a tiny AST-lite parser, and pip-installs whatever is missing — every time the file changes. Point it at a script an LLM is iterating on and the venv converges as the code does.
Why
Claude, Codex, Cursor and other coding agents can already run shell commands, create a .venv, and ask for approval before sensitive operations. What they do not share is durable Python environment state.
Sandboxing protects the machine. venv-manager protects the workflow: it gives every agent the same environments, metadata, package history and recovery path, independent of the client that happens to be running.
Two failure modes drove this tool:
Human sprawl. Venvs multiply across
~, cache directories eat GB, activation syntax varies by shell, and cloning "the env that worked" means copy-pastingpip freezebetween terminals.Agent sprawl. AI agents can install into the wrong interpreter, leave partial changes behind, and lose environment context when you switch client or start a new session.
venv-manager solves (1) with a clean CLI and (2) with a shared Model Context Protocol server, a persistent registry, typed snapshots and diffs, reversible package changes, ephemeral venvs with OS-level sandboxing, and a file watcher that keeps a venv in sync with evolving code.
What the agent sandbox does not solve
Agent capability | Shared environment control |
Approves or blocks a shell command | Records which environment belongs to which project |
Restricts filesystem and network access | Preserves state across Claude, Codex and other clients |
Creates a venv when prompted | Tracks creation and real last-use metadata |
Runs | Shows package-level changes between snapshots |
Stops an unsafe action | Rolls a damaged environment back to a known state |
The two layers complement each other: agent permissions control what may happen now; venv-manager records what exists, what changed, and how to recover.
Related MCP server: Sympathy-MCP
Install
Homebrew (macOS, Linux):
brew install jacopobonomi/tap/venv-managerOne-line install script (macOS, Linux):
curl -sSL https://raw.githubusercontent.com/jacopobonomi/venv_manager/main/install.sh | bashFrom source:
git clone https://github.com/jacopobonomi/venv_manager && cd venv_manager
make installRequires Go 1.24+ to build, Python 3.x at runtime.
AI integration
MCP server
Exposes venv operations as native Model Context Protocol tools. Claude, Codex, Cursor, Zed and other MCP clients call the same typed tools and operate on the same persistent environment state instead of guessing shell invocations independently.
Wire it up in Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"venv-manager": {
"command": "venv-manager",
"args": ["mcp", "--policy", "safe"]
}
}
}Tools exposed (JSON-RPC 2.0 over stdio):
Tool | Purpose |
| Names of all managed venvs. |
|
|
|
|
|
|
| `{name, packages[] |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Persistent project, tag, creation, and last-used metadata. |
|
|
| Python versions on |
The server defaults to safe policy. Installation, rollback, removal, and arbitrary execution require confirm: true. Use --policy read-only for inspection-only clients, --policy full for unrestricted compatibility, and repeat --allow-tool NAME to expose only an explicit subset. These policies are defense in depth: they remain consistent even when different clients have different approval settings.
Implementation uses zero third-party MCP dependencies. Newline-delimited JSON-RPC 2.0 on stdin/stdout.
Ephemeral execution (uvx-style, sandboxed)
# create → install → run → destroy, all in one call
venv-manager exec --with requests -- python -c "import requests; print(requests.__version__)"
# with an OS sandbox: no network, no writes outside /tmp + the ephemeral venv
venv-manager exec --sandbox --with pandas -- python untrusted.py--sandbox uses sandbox-exec on macOS and bwrap on Linux. Deny-by-default profile with explicit allow-lists for the venv path, /tmp, and process management. Network is unshared.
File watcher
venv-manager watch app.py --venv myenvfsnotify on the parent directory (survives editor atomic-rename writes), 500 ms debounce, then:
AST-lite regex scan of
.pyfiles (skips docstrings, relative imports, local modules/packages, and vendored dirs like.venv,.git,__pycache__,node_modules)Filter against a stdlib module set
Resolve import-name → pip-package aliases (
cv2→opencv-python,sklearn→scikit-learn,PIL→Pillow,bs4→beautifulsoup4,yaml→PyYAML, ...)Diff against installed packages
pip installthe delta
The venv is always a superset of the current file's requirements. This is the loop the demo GIF above exercises.
Persistent registry
Every environment is tracked in ~/.venvs/.venv-manager/registry.json with creation and last-used timestamps, an optional project path, and tags. Writes are atomic and the registry reconciles itself with live venv directories.
venv-manager registry
venv-manager registry set research --project ~/work/paper --tag data,ai
venv-manager registry researchprune uses registry last_used_at rather than directory modification time when metadata is available.
JSON snapshot as a single-call context primer
venv-manager describe myenv{
"name": "myenv",
"path": "/Users/me/.venvs/myenv",
"python_version": "3.12.6",
"python_path": "/Users/me/.venvs/myenv/bin/python",
"pip_path": "/Users/me/.venvs/myenv/bin/pip",
"packages": ["requests==2.34.2", "rich==15.0.0", ...],
"package_count": 12,
"size_bytes": 45123456,
"size_human": "43.03 MB",
"modified_at": "2026-07-20T15:41:35Z",
"freeze_hash": "sha256:2c58d830...",
"activation": {
"bash": "source '/Users/me/.venvs/myenv/bin/activate'",
"zsh": "source '/Users/me/.venvs/myenv/bin/activate'",
"fish": "source '/Users/me/.venvs/myenv/bin/activate.fish'"
}
}One tool call, everything an agent needs to reason about the environment. freeze_hash lets an agent detect drift between two describe calls in O(1) instead of diffing package lists.
Commands
Command | Description |
| Create a venv. Uses |
| List venvs. |
| Delete a venv. |
| Rename and re-generate activation scripts via |
| Fresh venv seeded with |
| Installed packages. |
|
|
| Upgrade outdated packages (per venv or all). |
| Purge pip cache + |
| Disk usage. |
| Print shell command for |
| Print |
| Execute in a venv without activating; inherited stdio. |
| Ephemeral venv run. |
| Full JSON snapshot (see above). |
| Extract third-party imports; check against venv. |
| Auto-install missing imports on file change. |
| Capture pip-freeze state. |
| List snapshots (newest first). |
| Install snapshot state first, then remove packages absent from it. |
| Diff snapshots, or compare one snapshot with current state. |
| Print portable manifest (name + python version + freeze) as JSON. |
| Recreate venv from manifest. |
| Report stale venvs; require |
| Show persistent creation, usage, project, and tag metadata. |
| Update project association and tags. |
| Diagnose python versions, uv, broken venvs. |
`config show | path |
| MCP server with read-only, safe, or full authorization policy. |
| Bubble Tea TUI browser. |
`completion [bash | zsh |
Most read commands also accept --json for stable, machine-parseable output.
Configuration
~/.config/venv-manager/config.json (respects $XDG_CONFIG_HOME and $VENV_MANAGER_CONFIG):
{
"base_dir": "/custom/path/to/venvs",
"default_python": "3.12",
"use_uv": true,
"prune_after_days": 90
}Bootstrap: venv-manager config init.
uv backend
If uv is on PATH and use_uv: true, create runs uv venv. Typically 10–100× faster than python -m venv on cold cache.
Development
make build # go build -o bin/venv-manager
make test # unit tests
make demo # regenerate scripts/demo/demo.gif via VHS
go test -tags=integration ./internal/manager/... # integration tests (real pip, real PyPI)CI runs go vet, go test -race on Ubuntu + macOS, and integration tests on Ubuntu with Python 3.12.
Architecture:
cmd/venv-manager/ cobra CLI
internal/manager/ core operations (create, install, snapshot, scan, watch, exec, describe, ...)
internal/config/ XDG-aware JSON config
internal/mcp/ JSON-RPC 2.0 MCP server (stdio)
internal/tui/ Bubble Tea browser
internal/utils/ platform helpers, size formattingLicense
MIT.
Author
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
MCP server for agentverse documentation, generated by doc2mcp.
Remote MCP server for supportsheep: run AI interviews and manage support content for your blog.
Hosted MCP server for live public-data APIs and Skills for AI agents.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceProduction-ready MCP server for secure Python code execution with artifact capture, virtual environment support, and LM Studio integration.11Apache 2.0
- FlicenseAqualityDmaintenanceAn MCP server for managing Incus virtual machines through structured tools for command execution, file management, and snapshot operations. It enables AI agents to puppeteer VMs on a masternode by wrapping the Incus CLI.9
- AlicenseBqualityDmaintenanceProduction-grade MCP server that gives AI agents safe access to your local dev environment: filesystem, databases, processes, and OpenAPI specs.15673MIT
- FlicenseBqualityFmaintenanceAn MCP server that manages Python virtual environments using uv, allowing LLMs to reliably resolve dependencies and update virtual environments.67
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jacopobonomi/venv_manager'
If you have feedback or need assistance with the MCP directory API, please join our Discord server