MySQL Query MCP server for AI assistants - execute read-only MySQL queries from Cursor IDE, Windsurf, or Claude Desktop
The server has 3 tools with complete input schemas and descriptions. Naming is action-verb based (query, info, environments) and reasonably clear. Descriptions exist but are minimal (10-50 chars), lacking context on WHEN to use each tool or what downstream decisions they enable. Parameter descriptions are present but sparse. No output schemas are documented, so LLMs cannot plan chained calls. Error handling and recovery guidance are absent. Security model (read-only enforcement) is appropriate but not explicitly validated in visible code. The server does not expose secrets as parameters (good), but lacks audit logging, permission gates, and structured error responses.
List available MySQL database environments
Get information about MySQL databases
Execute read-only SQL queries against MySQL databases
Output schemas not documented. LLMs cannot see what fields query, info, or environments return, blocking downstream tool chaining and forcing exploration calls.
Minimal descriptions lack context on WHEN to use each tool. 'Get information about MySQL databases' (info) doesn't distinguish it from query. Description should explain: get info first to discover table names, then call query to fetch rows.
No error handling guidance. If a query fails with 'syntax error' or 'permission denied', the tool returns an error but gives no recovery hint (e.g., 'check SQL syntax' or 'verify environment access'). Agents have no actionable next step.
Parameter 'environment' enum is hard-coded in schema but not validated against what's actually configured. If an operator misconfigures .env with only 'local' and 'staging', the tool still accepts 'production', then fails at runtime with a generic error.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 45 | - | v1 |
No audit logging of tool calls. In src/index.ts, debug() is called but only for startup. No logging of who called which tool, with which SQL, at what time, or what result was returned. Compliance and incident response need tool call traces.
Query tool lacks explicit timeout validation. 'timeout' parameter defaults to 30000ms but has no min/max constraint in the schema. An LLM could pass timeout=1 or timeout=999999, causing unexpected behavior or resource exhaustion.
Read-only enforcement (SELECT and SHOW only) is mentioned in the query description but not validated by the visible code. If validation is missing or incomplete, an LLM could exploit a gap to execute UPDATE or DROP statements.