An MCP server that provides tools to query and explore PostgreSQL databases with safety constraints
The PostgreSQL MCP server defines 3 tools with clear read-only semantics and basic input validation. Tool names follow verb-noun convention (postgres_query, list_tables, describe_table), which is good. However, there are significant gaps: parameter descriptions are minimal, output schemas are undocumented in the tool definitions, and error handling lacks recovery guidance. The descriptions are adequate (50-80 chars) but do not explain when/why to use each tool or what the LLM can expect in responses. The `postgres_query` tool has a query parameter with a basic description, but there is no documentation of the output structure (columns, rows, count fields). The `list_tables` and `describe_table` tools have no input parameters documented beyond what's visible in the parameter schema. Error messages returned are somewhat helpful (e.g., including schema info on column/table errors), but lack explicit guidance on retry strategies or next steps for the agent.
Describe the columns of a specified table
List all tables in the PostgreSQL database
Execute a SQL query against the PostgreSQL database
Output schemas are not documented in tool definitions. Tools return structured JSON (QueryResult, array of column objects) but LLMs have no formal specification of response fields, types, or format.
Parameter descriptions are present but minimal and lack constraint details. For example, 'query' parameter does not document whether CTEs must use specific syntax, maximum query length, or timeout behavior.
Error handling returns error text but does not categorize as retryable, user-fixable, or fatal. When a query fails due to a missing column, the tool includes schema info, but does not explain that the LLM should retry with corrected SQL or ask the user to clarify the intended table/column.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 39 | - | v1 |
The isSafeQuery() validation uses regex patterns to block dangerous SQL operations. This is reasonable, but the error messages do not suggest what the LLM should do next (e.g., 'This tool only supports read-only SELECT queries. To modify data, use a different tool or application.').
Tool descriptions do not explain the difference between list_tables (all tables) and describe_table (columns of one table), or provide guidance on typical usage sequence. An LLM might not know to call list_tables first to discover table names.