Metabase Ai Assistant — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Metabase Ai Assistant (Plugin) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center">
134 Tools • MCP SDK v1.26.0 • AI-Powered SQL • Structured Output • Enterprise Security
Turn your AI assistant into a Metabase power user. Generate SQL from natural language, create dashboards, manage users, and automate BI workflows.
📦 Install Now • 📖 Documentation • 🎯 Features • ⭐ Star Us
</div>
"I analyzed every Metabase MCP server on the market. This one has 4x more tools and features than any competitor."
| Feature | This Project | Other MCP Servers |
|---|---|---|
| Total Tools | 134 ✅ | 6-30 |
| AI SQL Generation | ✅ | ❌ |
| AI SQL Optimization | ✅ | ❌ |
| Dashboard Templates | ✅ | ❌ |
| User Management | ✅ | ❌ |
| Workspace Export/Import | ✅ | ❌ |
| Read-Only Security Mode | ✅ | ✅ |
| Response Caching | ✅ | ✅ |
| Activity Logging | ✅ | ❌ |
| Metadata Analytics | ✅ | ❌ |
| Parametric Questions | ✅ | ❌ |
| Environment Comparison | ✅ | ❌ |
| Structured Output (JSON) | ✅ | ❌ |
| Tool Annotations | ✅ | ❌ |
npx metabase-ai-assistant{
"mcpServers": {
"metabase": {
"command": "npx",
"args": ["-y", "metabase-ai-assistant"],
"env": {
"METABASE_URL": "https://your-metabase.com",
"METABASE_API_KEY": "mb_your_api_key"
}
}
}
}That's it! Your AI assistant now has full Metabase superpowers. 🦸
You: "Show me total revenue by product category for the last 30 days"
AI: Uses ai_sql_generate → Runs query → Returns formatted resultsYou: "Create an executive dashboard for our e-commerce sales"
AI: Uses mb_dashboard_template_executive → Creates fully configured dashboardYou: "What tables are related to 'orders' and show their relationships"
AI: Uses db_relationships_detect → Returns complete ER diagram infoYou: "DROP TABLE users"
AI: 🔒 Blocked - Read-only mode active🆕 All tools include MCP annotations andtitle. 16 priority tools supportoutputSchema+structuredContentfor typed JSON responses.
<details> <summary><b>📊 Database Operations (25 tools)</b></summary>
| Tool | Description |
|---|---|
db_list | List all databases |
db_schemas | Get schemas in a database |
db_tables | Get tables with fields |
sql_execute | Execute SQL queries |
db_table_create | Create tables (AI-prefixed) |
db_view_create | Create views |
db_matview_create | Create materialized views |
db_index_create | Create indexes |
db_vacuum_analyze | VACUUM and ANALYZE |
db_query_explain | EXPLAIN query plans |
db_table_stats | Table statistics |
db_index_usage | Index usage analysis |
db_schema_explore | Fast schema exploration |
db_schema_analyze | Deep schema analysis |
db_relationships_detect | Detect foreign keys |
| ...and more |
</details>
<details> <summary><b>🤖 AI-Powered Features (5 tools)</b></summary>
| Tool | Description |
|---|---|
ai_sql_generate | Natural language → SQL |
ai_sql_optimize | Query optimization suggestions |
ai_sql_explain | Explain SQL in plain English |
ai_relationships_suggest | Suggest table relationships |
mb_auto_describe | Auto-generate descriptions |
</details>
<details> <summary><b>📋 Question/Card Management (12 tools)</b></summary>
| Tool | Description |
|---|---|
mb_question_create | Create new questions |
mb_questions | List all questions |
mb_question_create_parametric | Parametric questions |
mb_card_get | Get card details |
mb_card_update | Update cards |
mb_card_delete | Delete cards |
mb_card_archive | Archive cards |
mb_card_data | Get card data as JSON |
mb_card_copy | Copy cards |
mb_card_clone | Clone cards |
| ...and more |
</details>
<details> <summary><b>📈 Dashboard Management (14 tools)</b></summary>
| Tool | Description |
|---|---|
mb_dashboard_create | Create dashboards |
mb_dashboards | List all dashboards |
mb_dashboard_get | Get dashboard details |
mb_dashboard_update | Update dashboards |
mb_dashboard_delete | Delete dashboards |
mb_dashboard_add_card | Add cards to dashboard |
mb_dashboard_add_filter | Add filters |
mb_dashboard_layout_optimize | Optimize layout |
mb_dashboard_template_executive | Executive templates |
| ...and more |
</details>
<details> <summary><b>👥 User & Permission Management (10 tools)</b></summary>
| Tool | Description |
|---|---|
mb_user_list | List users |
mb_user_get | Get user details |
mb_user_create | Create users |
mb_user_update | Update users |
mb_user_disable | Disable users |
mb_permission_group_list | List groups |
mb_permission_group_create | Create groups |
| ...and more |
</details>
<details> <summary><b>📊 Metadata Analytics (14 tools)</b></summary>
| Tool | Description |
|---|---|
mb_meta_overview | Instance health check |
mb_meta_query_performance | Query analytics |
mb_meta_content_usage | Content usage stats |
mb_meta_user_activity | User activity |
mb_meta_table_dependencies | Table dependencies |
mb_meta_impact_analysis | Breaking change analysis |
mb_meta_optimization_recommendations | Index suggestions |
mb_meta_export_workspace | Backup to JSON |
mb_meta_import_preview | Import dry-run |
mb_meta_compare_environments | Dev vs Prod diff |
mb_meta_auto_cleanup | Safe cleanup |
| ...and more |
</details>
| Feature | Description |
|---|---|
| 🔒 Read-Only Mode | Blocks INSERT, UPDATE, DELETE, DROP (default: enabled) |
| 🏷️ AI Prefix | All AI-created objects use claude_ai_ prefix |
| ✅ Explicit Approval | Destructive operations require confirmation |
| 📝 Activity Logging | Full audit trail of all operations |
| 🔐 Env Validation | Zod-validated environment variables |
| 💾 Auto-Backup | Prompts for backup before destructive ops |
# Enable/disable read-only mode
METABASE_READ_ONLY_MODE=true # Default: blocks write ops
METABASE_READ_ONLY_MODE=false # Allow write operationsCreate a .env file:
# Required
METABASE_URL=https://your-metabase.com
METABASE_API_KEY=mb_your_api_key
# Or use username/password
# [email protected]
# METABASE_PASSWORD=your_password
# Security (defaults to true)
METABASE_READ_ONLY_MODE=true
# AI Features (optional)
ANTHROPIC_API_KEY=sk-ant-...
OPENAI_API_KEY=sk-...
# Performance (optional)
CACHE_TTL_MS=600000 # 10 minutesnpm install -g metabase-ai-assistantdocker run -e METABASE_URL=... -e METABASE_API_KEY=... ghcr.io/enessari/metabase-ai-assistantgit clone https://github.com/enessari/metabase-ai-assistant.git
cd metabase-ai-assistant
npm install
npm run mcpmetabase-ai-assistant/
├── src/
│ ├── mcp/
│ │ ├── server.js # MCP Server entry point
│ │ ├── tool-registry.js # 134 tool definitions + annotations + outputSchema
│ │ ├── tool-router.js # Dynamic routing with read-only gate
│ │ └── handlers/ # 15 modular handler files
│ ├── utils/
│ │ ├── structured-response.js # Structured output (MCP 2025-06-18)
│ │ ├── cache.js # TTL-based caching
│ │ ├── config.js # Zod validation
│ │ └── response-optimizer.js # Compact response formatting
│ └── metabase/
│ └── client.js # Metabase API clientWe welcome contributions! See CONTRIBUTING.md for guidelines.
# Fork, clone, install
git clone https://github.com/YOUR_USERNAME/metabase-ai-assistant.git
npm install
# Create feature branch
git checkout -b feature/amazing-feature
# Test and submit PR
npm test
git push origin feature/amazing-featureApache License 2.0 - see LICENSE
<div align="center">
Built with ❤️ by [Abdullah Enes SARI](https://github.com/enessari) @ [ONMARTECH LLC](https://onmartech.com)
Keywords: Metabase MCP Server, Model Context Protocol, AI SQL Generation, Business Intelligence, Claude AI, Cursor AI, Natural Language SQL, Dashboard Automation, PostgreSQL, Data Analytics, LLM Tools
</div>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.