.vscode — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .vscode (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for the dbatools PowerShell module.
Exposes dbatools commands as MCP tools so AI assistants (GitHub Copilot, Claude, etc.) can discover, explain, and execute dbatools commands directly — with all metadata sourced from dbatools' own comment-based help.
Get-Help -Fullconfirm: true to executeSqlCredential: { username, password } for SQL auth instancespwsh)Install-Module dbatools -Scope CurrentUser# 1. Clone the repo
git clone https://github.com/Dataplat/dbatools-mcp-server.git
cd dbatools-mcp-server
# 2. Install Node dependencies
npm install
# 3. Generate the help index from your local dbatools installation
npm run refresh-help
# 4. Build
npm run buildThen open the folder in VS Code — the .vscode/mcp.json file automatically registers the MCP server.
The included .vscode/mcp.json registers the server as a local STDIO MCP server. Open this folder in VS Code and the server will appear in the GitHub Copilot MCP panel.
{
"servers": {
"dbatools": {
"type": "stdio",
"command": "node",
"args": ["${workspaceFolder}/dist/server.js"],
"env": {
"DBATOOLS_SAFE_MODE": "true",
"MAX_OUTPUT_ROWS": "100",
"COMMAND_TIMEOUT_SECONDS": "60"
}
}
}
}All settings are controlled via environment variables (set in .vscode/mcp.json or your shell):
| Variable | Default | Description |
|---|---|---|
PWSH_EXE | pwsh | Path to PowerShell executable |
DBATOOLS_SAFE_MODE | true | When true, non-readonly commands require confirm: true |
MAX_OUTPUT_ROWS | 100 | Maximum rows returned per command execution |
COMMAND_TIMEOUT_SECONDS | 60 | Seconds before PowerShell process is killed |
The help index (generated/dbatools-help.json) is generated from your locally installed dbatools module. Re-run whenever dbatools is updated:
Update-Module dbatools -Scope CurrentUser
npm run refresh-helpThe server detects version mismatches at runtime and warns you when the index is stale.
Commands are automatically classified by verb:
| Risk Level | Verbs | Behavior |
|---|---|---|
readonly | Get, Test, Find, Compare, … | Always allowed |
change | Set, New, Add, Copy, Enable, … | Requires confirm: true in safe mode |
destructive | Remove, Drop, Disable, Reset, … | Requires confirm: true in safe mode |
For SQL-auth-only instances (e.g. Docker), pass credentials via the SqlCredential parameter:
{
"SqlInstance": "localhost,1433",
"SqlCredential": { "username": "<SqlLogin>", "password": "YourPassword" }
}dbatools-mcp-server/
├── src/
│ ├── server.ts # MCP server entry point, tool definitions
│ ├── powershell.ts # PowerShell process runner, health checks, version detection
│ ├── help-indexer.ts # Help manifest loader and command search
│ ├── tool-registry.ts # Risk classification, safe argument builder
│ └── types.ts # Shared TypeScript interfaces
├── scripts/
│ └── refresh-help.ps1 # Generates generated/dbatools-help.json
├── generated/ # Help index (gitignored, generated locally)
├── .vscode/
│ └── mcp.json # VS Code MCP local server registration
└── dist/ # Compiled output (gitignored)Contributions are welcome! Please open an issue first for significant changes.
This project follows the same community spirit as dbatools.
MIT — © 2026 DataPlat contributors
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.