Mcp Turso Cloud — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Turso Cloud (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server that provides integration with Turso databases for LLMs. This server implements a two-level authentication system to handle both organization-level and database-level operations, making it easy to manage and query Turso databases directly from LLMs.
<a href="https://glama.ai/mcp/servers/hnkzlqoh92"> <img width="380" height="200" src="https://glama.ai/mcp/servers/hnkzlqoh92/badge" alt="mcp-turso-cloud MCP server" /> </a>
specific databases
(read-only operations)
UPDATE, DELETE, etc.)
vector extensions
This server implements a security-focused separation between read-only and destructive database operations:
execute_read_only_query for SELECT and PRAGMA queries (safe,read-only operations)
execute_query for INSERT, UPDATE, DELETE, CREATE, DROP, andother operations that modify data
This separation allows for different permission levels and approval requirements:
ALWAYS CAREFULLY READ AND REVIEW SQL QUERIES BEFORE APPROVING THEM! This is especially critical for destructive operations that can modify or delete data. Take time to understand what each query does before allowing it to execute.
The server implements a sophisticated authentication system:
This server requires configuration through your MCP client. Here are examples for different environments:
Add this to your Cline/Claude Desktop MCP settings:
{
"mcpServers": {
"mcp-turso-cloud": {
"command": "npx",
"args": ["-y", "mcp-turso-cloud"],
"env": {
"TURSO_API_TOKEN": "your-turso-api-token",
"TURSO_ORGANIZATION": "your-organization-name",
"TURSO_DEFAULT_DATABASE": "optional-default-database"
}
}
}
}For WSL environments, add this to your Claude Desktop configuration:
{
"mcpServers": {
"mcp-turso-cloud": {
"command": "wsl.exe",
"args": [
"bash",
"-c",
"TURSO_API_TOKEN=your-token TURSO_ORGANIZATION=your-org node /path/to/mcp-turso-cloud/dist/index.js"
]
}
}
}The server requires the following environment variables:
TURSO_API_TOKEN: Your Turso Platform API token (required)TURSO_ORGANIZATION: Your Turso organization name (required)TURSO_DEFAULT_DATABASE: Default database to use when none isspecified (optional)
TOKEN_EXPIRATION: Expiration time for generated database tokens(optional, default: '7d')
TOKEN_PERMISSION: Permission level for generated tokens (optional,default: 'full-access')
The server implements MCP Tools organized by category:
#### list_databases
Lists all databases in your Turso organization.
Parameters: None
Example response:
{
"databases": [
{
"name": "customer_db",
"id": "abc123",
"region": "us-east",
"created_at": "2023-01-15T12:00:00Z"
},
{
"name": "product_db",
"id": "def456",
"region": "eu-west",
"created_at": "2023-02-20T15:30:00Z"
}
]
}#### create_database
Creates a new database in your organization.
Parameters:
name (string, required): Name for the new databasegroup (string, optional): Group to assign the database toregions (string[], optional): Regions to deploy the database toExample:
{
"name": "analytics_db",
"group": "production",
"regions": ["us-east", "eu-west"]
}#### delete_database
Deletes a database from your organization.
Parameters:
name (string, required): Name of the database to deleteExample:
{
"name": "test_db"
}#### generate_database_token
Generates a new token for a specific database.
Parameters:
database (string, required): Database nameexpiration (string, optional): Token expiration timepermission (string, optional): Permission level ('full-access' or'read-only')
Example:
{
"database": "customer_db",
"expiration": "30d",
"permission": "read-only"
}#### list_tables
Lists all tables in a database.
Parameters:
database (string, optional): Database name (uses context if notprovided)
Example:
{
"database": "customer_db"
}#### execute_read_only_query
Executes a read-only SQL query (SELECT, PRAGMA) against a database.
Parameters:
query (string, required): SQL query to execute (must be SELECT orPRAGMA)
params (object, optional): Query parametersdatabase (string, optional): Database name (uses context if notprovided)
Example:
{
"query": "SELECT * FROM users WHERE age > ?",
"params": { "1": 21 },
"database": "customer_db"
}#### execute_query
Executes a potentially destructive SQL query (INSERT, UPDATE, DELETE, CREATE, etc.) against a database.
Parameters:
query (string, required): SQL query to execute (cannot be SELECTor PRAGMA)
params (object, optional): Query parametersdatabase (string, optional): Database name (uses context if notprovided)
Example:
{
"query": "INSERT INTO users (name, age) VALUES (?, ?)",
"params": { "1": "Alice", "2": 30 },
"database": "customer_db"
}#### describe_table
Gets schema information for a table.
Parameters:
table (string, required): Table namedatabase (string, optional): Database name (uses context if notprovided)
Example:
{
"table": "users",
"database": "customer_db"
}#### vector_search
Performs vector similarity search using SQLite vector extensions.
Parameters:
table (string, required): Table namevector_column (string, required): Column containing vectorsquery_vector (number[], required): Query vector for similaritysearch
limit (number, optional): Maximum number of results (default: 10)database (string, optional): Database name (uses context if notprovided)
Example:
{
"table": "embeddings",
"vector_column": "embedding",
"query_vector": [0.1, 0.2, 0.3, 0.4],
"limit": 5,
"database": "vector_db"
}npm installnpm run buildnpm run devnpm run buildnpm publishIf you encounter authentication errors:
permissions
If you have trouble connecting to databases:
Contributions are welcome! Please feel free to submit a Pull Request.
MIT License - see the LICENSE file for details.
Built on:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.