Db Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Db Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for MySQL, PostgreSQL, MongoDB, and SQLite databases. One instance per database, no Docker required.
uvx db-mcp-serverConfigure via environment variables. Each instance connects to a single database.
| Variable | Required | Default | Description |
|---|---|---|---|
DB_TYPE | Yes | — | mysql |
DB_DATABASE | Yes | — | Database name |
DB_PASSWORD | Yes | — | Password |
DB_HOST | No | localhost | Host |
DB_PORT | No | 3306 | Port |
DB_USER | No | root | User |
DB_MODE | No | read-only | read-only or read-write |
| Variable | Required | Default | Description |
|---|---|---|---|
DB_TYPE | Yes | — | postgresql |
DB_DATABASE | Yes | — | Database name |
DB_PASSWORD | Yes | — | Password |
DB_HOST | No | localhost | Host |
DB_PORT | No | 5432 | Port |
DB_USER | No | postgres | User |
DB_MODE | No | read-only | read-only or read-write |
| Variable | Required | Default | Description |
|---|---|---|---|
DB_TYPE | Yes | — | mongodb |
DB_DATABASE | Yes | — | Database name |
DB_URL | Yes | — | Connection URL (mongodb://...) |
DB_MODE | No | read-only | read-only or read-write |
| Variable | Required | Default | Description |
|---|---|---|---|
DB_TYPE | Yes | — | sqlite |
DB_PATH | Yes | — | Path to .db file (local or remote with SSH) |
DB_DATABASE | No | filename | Display name |
DB_MODE | No | read-only | read-only or read-write |
Optionally connect through an SSH bastion host. Set SSH_HOST to activate.
For SQLite over SSH, the remote .db file is downloaded via SFTP before querying. In read-write mode, changes are uploaded back on shutdown.
| Variable | Required | Default | Description |
|---|---|---|---|
SSH_HOST | No | — | SSH bastion host (activates tunneling) |
SSH_PORT | No | 22 | SSH port |
SSH_USER | No | Current OS user | SSH username |
SSH_KEY | No | — | Path to private key (~/.ssh/id_rsa) |
SSH_PASSWORD | No | — | SSH password (if no key) |
At least one of SSH_KEY or SSH_PASSWORD is required when SSH_HOST is set. SSH tunneling is not supported for MongoDB.
{
"mcpServers": {
"db-local": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": {
"DB_TYPE": "sqlite",
"DB_PATH": "/path/to/database.db"
}
}
}
}{
"mcpServers": {
"db-remote": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": {
"DB_TYPE": "sqlite",
"DB_PATH": "/remote/path/to/database.db",
"SSH_HOST": "server.example.com",
"SSH_USER": "deploy",
"SSH_KEY": "~/.ssh/id_rsa"
}
}
}
}{
"mcpServers": {
"db-prod": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": {
"DB_TYPE": "mysql",
"DB_MODE": "read-only",
"DB_HOST": "db.example.com",
"DB_PORT": "3306",
"DB_USER": "root",
"DB_PASSWORD": "secret",
"DB_DATABASE": "myapp"
}
}
}
}{
"mcpServers": {
"db-behind-bastion": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": {
"DB_TYPE": "postgresql",
"DB_HOST": "10.0.0.5",
"DB_PORT": "5432",
"DB_USER": "postgres",
"DB_PASSWORD": "secret",
"DB_DATABASE": "myapp",
"SSH_HOST": "bastion.example.com",
"SSH_USER": "deploy",
"SSH_KEY": "~/.ssh/id_rsa"
}
}
}
}For multiple databases, add multiple instances:
{
"mcpServers": {
"db-prod": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": { "DB_TYPE": "mysql", "DB_DATABASE": "prod", "..." : "..." }
},
"db-analytics": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": { "DB_TYPE": "postgresql", "DB_DATABASE": "analytics", "..." : "..." }
},
"db-staging": {
"command": "uvx",
"args": ["db-mcp-server"],
"env": { "DB_TYPE": "mongodb", "DB_DATABASE": "staging", "..." : "..." }
}
}
}DB_MODE=read-writeDB_MODE=read-writeDB_MODE=read-writeMIT
<!-- mcp-name: io.github.stucchi/db -->
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.