An MCP server providing tools for database profile management, SQL execution, schema analysis, query optimization, data lineage tracking, and database schema discovery across PostgreSQL, MySQL, MariaDB, and SQLite databases.
This database MCP server has 20 tools with generally clear names and structured parameters, but quality is highly inconsistent. Tool descriptions range from adequate (execute-sql, configure-profile) to vague/ambitious (discover-insights, analyze-data-lineage). Most tools lack documented output schemas, critical for an MCP server where downstream tools depend on understanding result structure. Parameter schemas are present but incomplete: many parameters lack type constraints (e.g., 'params' array in execute-sql has no item type), and several tools have parameters without descriptions. Security is a concern: passwords are exposed as plain-text parameters despite claims of AES-256 encryption (no evidence in source). Error handling is undocumented across all tools. Several tools (smart-query-builder, discover-insights, analyze-schema) are vaguely defined and promise AI-like 'discovery' without clear input/output contracts, these appear more like speculative feature placeholders than production-ready tools. Average tool score: 48/100.
Analyze and track data lineage across tables and views in a database.
Perform comprehensive schema analysis including statistics, data quality metrics, relationships, and query suggestions.
Create, update, delete, or clone a database connection profile. Profiles store connection details (host, port, credentials) used by all other database tools.
Describe columns, types, keys, and metadata for a specific table. Returns column names, data types, nullability, keys, defaults, and other attributes.
Discover data patterns, anomalies, and business insights from database content.
Discover and suggest join relationships between tables based on schema and data patterns.
Password parameter exposed as plain text despite AES-256 encryption claims. Tool description states passwords are 'stored encrypted with AES-256' but parameter definition accepts password as a string parameter, which enters MCP traces and logs. Violates secret-injection pattern.
Output schemas are completely undocumented across all 20 tools. MCP requires documented return types so downstream tools understand what fields to extract. Current tool definitions have no 'output' or 'returns' field, forcing agents to guess result structure.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 40 | - | v1 |
Execute arbitrary SQL queries on a selected database profile. Supports parameterized queries to prevent SQL injection. Returns column names, row data, and affected row count.
Execute queries across multiple configured database profiles.
Get detailed help and usage information for a specific tool.
List all databases available on a configured database profile.
List all configured database profiles. Returns profile names and database types. No parameters required.
List all schemas in a PostgreSQL database.
List all tables (and views) in a database. Returns table names with their schema context. Works across MySQL, MariaDB, PostgreSQL, and SQLite.
List all available tools provided by this MCP server.
Retrieve information about the MCP server, its capabilities, and configuration.
Analyze and provide optimization suggestions for SQL queries.
Sample and retrieve representative rows from a table with filtering and formatting options.
Build SQL queries using natural language or structured parameters.
Track and monitor database schema changes over time.
Validate SQL query syntax and check for potential errors.
'params' parameter in execute-sql is an untyped array. Schema specifies type=array but no itemType or description of what each element should be (string? number? JSON?). Agents cannot construct valid param arrays without examples.
Three tools (smart-query-builder, discover-insights, analyze-data-lineage) have vague descriptions and unclear contracts. 'Discover data patterns and anomalies' (discover-insights) lacks specification of what patterns, what output structure, when to use it instead of analyze-schema. These appear speculative rather than production-ready.
No error handling documentation. Tool descriptions do not specify retryable vs fatal errors, what invalid inputs look like, or how to recover from failures. No 'recovery-guide' pattern applied.
federated-query parameter 'sql_template' is undescribed. No guidance on what placeholders mean, how to structure multi-database queries, or which databases need identical schemas. High ambiguity for LLM usage.
analyze-schema parameters 'sample_size' and 'profiling' lack constraints. No min/max for sample_size, no guidance on what profiling entails or performance impact. Agents may pass unreasonable values (e.g., sample_size=1000000).
Several 'discovery' tools (discover-joins, discover-insights, track-schema-changes, analyze-data-lineage) lack idempotency contracts and may produce different results on repeated calls or have side effects not documented.
Tool 'smart-query-builder' provides no mechanism to validate the generated query before execution. Users could receive syntactically invalid SQL without guidance on how to correct it.
No pagination guidance for list-* tools. list-tables, list-databases, list-schemas lack limit/offset parameters. Large database inventories could exceed context windows without pagination support.