Db Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Db Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server that gives LLM agents read access to any database, with built-in gates for writes.
LLMs handle read-only database work: schema exploration, query writing, data analysis. A stray DELETE or DROP from an agent can wipe production data. db-mcp draws a hard line: reads go through, writes require the agent to show you exactly what it plans to do and wait for your explicit approval.
SELECT, EXPLAIN, SHOW, DESCRIBE, and WITH (when safe).DB_<NAME>=<url> environment variables. No config files to manage.| Database | URL format | Extra install |
|---|---|---|
| PostgreSQL | postgresql://user:pass@host:5432/db | included |
| SQLite | sqlite:///./path/to/file.db | included (built-in) |
| Oracle | oracle+oracledb://user:pass@host:1521/service | [oracle] |
| MySQL | mysql+pymysql://user:pass@host:3306/db | [mysql] |
| SQL Server | mssql+pyodbc://user:pass@host/db?driver=... | [mssql] |
| Snowflake | snowflake://user:pass@account/db/schema | snowflake-sqlalchemy |
Any other database works too. Install the right SQLAlchemy driver and use its URL format.
# Clone the repo
git clone [email protected]:paulushcgcj/db-mcp.git
cd db-mcp
# Run with a local SQLite database
DB_LOCAL=sqlite:///./test.db ./run.shThe server starts and your LLM tool can list tables, describe schemas, and run read queries against local.
Set DB_<NAME>=<url> environment variables. The part after DB_ (lowercased) is the name you reference in prompts.
DB_PROD=postgresql://user:[email protected]:5432/production
DB_LOCAL=sqlite:///./dev.db
DB_MAX_ROWS=1000 # optional, default 500Put these in a .env file if you run the server manually.
run.sh is the recommended launcher. It syncs dependencies, detects which database drivers your DB_* env vars need, installs them if missing, and hands off to the MCP server.
# Run manually
DB_LOCAL=sqlite:///./test.db ./run.sh
# Or with a .env file
./run.shWhen your IDE launches db-mcp, point it at run.sh instead of calling uv run db-mcp directly. The script handles driver installation so you don't have to pip install extras like [oracle] or [mysql] by hand.
<details> <summary><strong>VS Code Copilot</strong></summary>
Add to .vscode/mcp.json (workspace) or ~/.vscode/mcp.json (global):
{
"servers": {
"db-mcp": {
"type": "stdio",
"command": "/absolute/path/to/db-mcp/run.sh",
"env": {
"DB_PROD": "postgresql://user:pass@host:5432/mydb",
"DB_LOCAL": "sqlite:///./local.db",
"DB_MAX_ROWS": "500"
}
}
}
}</details>
<details> <summary><strong>OpenCode</strong></summary>
Add to ~/.config/opencode/opencode.jsonc or .opencode.json in your project:
{
"mcp": {
"db-mcp": {
"type": "local",
"command": ["/absolute/path/to/db-mcp/run.sh"],
"environment": {
"DB_PROD": "postgresql://user:pass@host:5432/mydb",
"DB_LOCAL": "sqlite:///./local.db",
"DB_MAX_ROWS": "500"
}
}
}
}</details>
| Tool | Description |
|---|---|
list_connections | List all configured DB connections |
list_tables | List tables and views in a connection |
describe_table | Show columns, PK, FKs, indexes for a table |
query | Execute read-only SQL (SELECT, EXPLAIN, etc.) |
preview_mutation | Preview a write/destructive query, get a confirmation token |
execute_mutation | Execute after you confirm (requires token from above) |
Every write or destructive query follows the same flow:
Agent calls preview_mutation(connection, sql)
→ Server returns a preview of the change + a one-time token (5-minute TTL)
Agent shows you the preview:
"This will DELETE 42 rows from orders. Do you confirm?"
You say yes.
Agent calls execute_mutation(connection, sql, token)
→ Server validates the token, executes, and consumes it.The token binds the connection name and the exact SQL to the approval. If the agent tries to run different SQL or target a different connection, the server rejects the token. Tokens expire after 5 minutes and can only be used once.
run.sh detects the URL scheme and installs the driver for you. For example, setting DB_SNOW=snowflake://... causes the script to install snowflake-sqlalchemy on first launch.
If you prefer to install manually:
uv pip install snowflake-sqlalchemyThe SQLAlchemy dialect registry resolves the driver from the URL prefix.
| Variable | Default | Description |
|---|---|---|
DB_<NAME> | — | Connection URL for a named database |
DB_MAX_ROWS | 500 | Max rows returned per query call |
See CONTRIBUTING.md for development setup, code style, and PR guidelines.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.