Sqldb Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Sqldb Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A read-only Model Context Protocol (MCP) server that exposes SQL database access to LLMs.
SELECT statements are allowed (enforced via AST-level SQL parsing with the correct dialect per DB type)skip / take parameters with automatic cap at 100 rowsmeta.totalCount so the LLM knows how many rows existquery, listTables, describeTable, explainQuery, exportQuery, saveQueryEvidence# Install globally
npm install -g @akrym1582/sqldb-mcp-server
# Or run directly with npx (no install needed)
npx @akrym1582/sqldb-mcp-servergit clone https://github.com/akrym1582/sqldb-mcp-server.git
cd sqldb-mcp-server
npm install
npm run build# 1. Install globally
npm install -g @akrym1582/sqldb-mcp-server
# 2. Configure environment variables (see below)
export DB_TYPE=postgresql
export DB_HOST=localhost
export DB_USER=myuser
export DB_PASSWORD=mypassword
export DB_NAME=mydb
# 3. Run
sqldb-mcp-serverOr use in your MCP client configuration (e.g. Claude Desktop claude_desktop_config.json):
{
"mcpServers": {
"sqldb": {
"command": "npx",
"args": ["-y", "@akrym1582/sqldb-mcp-server"],
"env": {
"DB_TYPE": "postgresql",
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_USER": "myuser",
"DB_PASSWORD": "mypassword",
"DB_NAME": "mydb"
}
}
}
}| Variable | Default | Description |
|---|---|---|
DB_TYPE | mssql | Database type: mssql, postgresql, or mysql |
DB_HOST | – | Database server hostname |
DB_PORT | 1433 / 5432 / 3306 | Database server port (default depends on DB_TYPE) |
DB_USER | – | Database username |
DB_PASSWORD | – | Database password |
DB_NAME | – | Database name |
DB_ENCRYPT | true for MSSQL/PostgreSQL, false for MySQL | Enables encrypted DB connections. MSSQL trusts the server certificate. PostgreSQL tries SSL first and falls back to plain if SSL is unavailable. MySQL uses TLS with certificate verification disabled when enabled. |
DB_QUERY_TIMEOUT | 30000 | Query timeout in milliseconds (used by query / explainQuery) |
EXPORT_QUERY_TIMEOUT | 300000 | Export query timeout in milliseconds (used by exportQuery; default 5 min) |
CACHE_TTL | 60 | Cache TTL in seconds |
DB_TYPE | Default DB_PORT |
|---|---|
mssql | 1433 |
postgresql | 5432 |
mysql | 3306 |
queryExecute a SELECT SQL statement.
{
"sql": "SELECT id, name FROM users WHERE active = 1",
"skip": 0,
"take": 10
}Response format (compact / token-efficient):
{
"meta": { "totalCount": 42, "returnedCount": 10, "skip": 0, "take": 10 },
"columns": ["id", "name"],
"rows": [[1, "Alice"], [2, "Bob"], ...]
}listTablesList all base tables in the database.
[{ "schema": "dbo", "name": "users" }, ...]describeTableDescribe a table's columns, indexes, foreign keys, check constraints, and size statistics.
{ "table": "dbo.users" }explainQueryReturn the estimated execution plan for a SELECT query without executing it.
{ "sql": "SELECT * FROM orders WHERE status = 'open'" }exportQueryStream a SELECT query result to a file. Designed for large datasets – there is no row-count limit and results are written directly to disk using Node.js streams.
{
"sql": "SELECT * FROM large_table",
"filepath": "/tmp/export.csv",
"format": "csv",
"options": { "delimiter": ",", "bom": false }
}format defaults to "csv" if omitted. "json" is also supported.
CSV options (all optional):
| Option | Default | Description |
|---|---|---|
delimiter | "," | Column separator |
nullValue | "" | String to write for NULL / undefined cells |
bom | false | Prepend UTF-8 BOM (useful for Excel) |
JSON options (all optional):
| Option | Default | Description |
|---|---|---|
pretty | false | Indent the output JSON |
Response format:
{
"filepath": "/tmp/export.csv",
"format": "csv",
"rowCount": 50000
}The tool uses a separate, longer-lived connection pool whose requestTimeout is controlled by EXPORT_QUERY_TIMEOUT (default 300 000 ms = 5 min). Increase this value for very large exports.
saveQueryEvidenceExecute a SELECT query and save the SQL plus the returned rows as a Markdown report file for test evidence.
{
"sql": "SELECT id, name FROM users LIMIT 10",
"filepath": "/tmp/query-evidence.md"
}Response format:
{
"filepath": "/tmp/query-evidence.md",
"rowCount": 10,
"previewRows": [
{ "id": 1, "name": "Alice" },
{ "id": 2, "name": "Bob" }
]
}If an error occurs, the tool returns the error message text instead of a success payload.
# Clone the repository
git clone https://github.com/akrym1582/sqldb-mcp-server.git
cd sqldb-mcp-server
# Install dependencies
npm install
# Configure environment
cp .env.example .env
# Edit .env with your DB credentials
# Run in dev mode (no compile step)
npm run dev
# Or build and run
npm run build
npm start
# Run unit tests
npm testsrc/
mcp/
server.ts # MCP server entry point
tools/
query.ts # query tool
listTables.ts # listTables tool
describeTable.ts # describeTable tool
explainQuery.ts # explainQuery tool
exportQuery.ts # exportQuery tool (streaming file export)
db/
index.ts # DB adapter factory (selects adapter from DB_TYPE)
types.ts # DB interfaces (including queryStream)
adapters/
mssql.ts # Microsoft SQL Server implementation
postgresql.ts # PostgreSQL implementation (pg + pg-cursor)
mysql.ts # MySQL implementation (mysql2)
utils/
row-result.ts # Compact columnar result format
sanitize.ts # AST-based SQL read-only validation (dialect-aware)
pagination.ts # skip/take normalisation
cache.ts # TTL in-memory cache
export-writer.ts # Streaming CSV / JSON file writer
__tests__/ # Unit tests~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.