MCP server for interacting with SQLite, SQL Server, PostgreSQL, and MySQL databases
This server has moderate definition quality with significant gaps. Parameter descriptions are entirely missing from the schema definitions shown in src/handlers/toolHandlers.ts, properties like 'query' and 'format' lack any description text. Output schemas are not documented at all. Error handling is present (formatErrorResponse utility) but the server provides no recovery guidance in error responses. The tool set lacks composition safeguards: destructive tools like drop_table and write_query have minimal safeguards, and there is no evidence of idempotency guarantees or confirmation patterns beyond a boolean flag. Security is a concern: raw SQL execution via 'query' parameters invites SQL injection unless validation happens inside tool implementations (not visible in the provided code). Overall, the definitions read like a thin wrapper over a database driver rather than a thoughtfully designed agent interface.
Modify existing table schema (add columns, rename tables, etc.)
Add a business insight to the memo
Create new tables in the database
View schema information for a specific table
Remove a table from the database with safety confirmation
Export query results to various formats (CSV, JSON)
List all business insights in the memo
All parameter descriptions are missing from schema definitions. The 'query', 'table_name', 'format', 'confirm', and 'insight' parameters have no descriptions in toolHandlers.ts. LLMs cannot infer parameter meaning from names alone.
Tool descriptions are all under 20 characters (e.g., 'Execute SELECT queries to read data from the database' is provided in the requirements but not visible in the code schema). The code schema shows empty or minimal descriptions. Descriptions must be 10 - 1024 characters and answer: What does it do? When should the LLM call it? What does it return?
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 19 | - | v1 |
Get a list of all tables in the database
Execute SELECT queries to read data from the database
Execute INSERT, UPDATE, or DELETE queries
Output schemas are not documented. The server returns results from tools (readQuery, writeQuery, etc.) but the schema definitions do not document what fields or structure the LLM should expect. Without documented output schemas, the LLM cannot reason about chaining tools.
Raw SQL query parameters (read_query, write_query, create_table, alter_table all accept a 'query' string) invite SQL injection. The code snippet does not show input validation or parameterized queries. Validate and reject suspicious patterns or use parameterized queries.
drop_table relies on a boolean 'confirm' flag for safety. A bare boolean is weak protection, the LLM could pass 'confirm=true' accidentally or maliciously. Consider adding a confirmation string (e.g., user must pass table name spelled backwards, or a confirmation token) to prevent accidental destruction.
Error handling does not guide recovery. The code uses formatErrorResponse() but does not show what that function returns. Try search_users() with a partial name.' A raw error code or stack trace gives the agent nothing to act on. Verify that all errors include actionable guidance.
No idempotency guarantees. Tools like write_query, create_table, and append_insight modify state but do not document whether repeated calls with identical parameters are idempotent. State whether each write tool is idempotent or require idempotency keys.
export_query 'format' parameter lacks enum validation description in the schema. The schema shows enum: ['csv', 'json'], which is good, but parameter description is missing entirely. Add descriptions like: 'Output format: csv (comma-separated values) or json (structured JSON object)'.