MCP server that allows Claude Desktop to connect to and query databases. Supports 17+ database types including MySQL, PostgreSQL, MongoDB, Oracle, SQL Server, SQLite, and others. Can run in MCP (stdio) mode or HTTP API mode.
This is a database connector MCP server with 9 tools spanning schema inspection, query execution, and connection management. Most tools have descriptions (in Chinese) and schemas, but several critical gaps limit production readiness: (1) Descriptions are often long and include unnecessary implementation details rather than LLM-optimized guidance. (2) Parameter descriptions exist but lack clarity on constraints, formats, and expected values. (3) No output schemas are documented for any tool, LLMs cannot predict what fields to expect from responses. (4) Error handling is absent from tool definitions, leaving agents without recovery guidance. (5) Security concerns: execute_query accepts raw SQL with optional parameterization but no validation hints; connect_database exposes credentials as parameters despite the pattern recommending secret injection. (6) Tool composition could be improved, execute_query is monolithic (SELECT/INSERT/UPDATE/DELETE all in one). The server does implement basic schema constraints (e.g., enum for database types in connect_database), but falls short of production-grade tool definitions.
清除 Schema 缓存。当数据库结构发生变化(如新增表、修改列)时,可以调用此工具清除缓存。
连接到数据库。支持动态指定数据库类型和连接参数,无需重启服务。如果当前已有连接,会自动断开旧连接再建立新连接。支持的数据库类型:mysql, postgres, redis, oracle, dm, sqlserver, mongodb, sqlite, kingbase, gaussdb, oceanbase, tidb, clickhouse, polardb, vastbase, highgo, goldendb。
断开当前数据库连接。断开后需要重新调用 connect_database 才能执行查询。
执行 SQL 查询或数据库命令。支持 SELECT、JOIN、聚合等查询操作。如果启用了写入模式,也可以执行 INSERT、UPDATE、DELETE 等操作。
获取当前数据库连接状态。返回是否已连接、数据库类型、地址、数据库名、权限模式等信息。
获取指定列的所有唯一值。用于了解 status、type、category 等枚举类型列的所有可能值,帮助生成准确的 WHERE 条件。例如:获取 orders.status 列的所有状态值(pending, shipped, delivered 等)。
No output schemas documented for ANY tool. LLMs cannot predict response structure, field names, or types. This forces agents to guess or request help after each call.
Credentials (user, password) are exposed as tool parameters in connect_database. Per security pattern, secrets must be server-side injected via environment variables or vault, not passed as parameters. Agent traces log all parameters, credentials will leak into logs.
execute_query tool accepts raw SQL and optional parameterization but provides no validation guidance or injection warnings in the description. Description mentions 'parameterized queries' but doesn't explain SQL injection risk or when to use params vs raw queries.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 61 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
获取表的示例数据(已自动脱敏)。用于了解数据格式,如日期格式(2024-01-01 vs 20240101)、ID格式(UUID vs 自增)、金额精度等。敏感数据(手机号、邮箱、身份证等)会自动脱敏保护隐私。
获取数据库结构信息,包括所有 Schema 中用户可访问的表名、列名、数据类型、主键、索引等元数据。在执行查询前调用此工具可以帮助理解数据库结构。结果会被缓存以提高性能。
获取指定表的详细信息,包括列定义、索引、预估行数等。用于深入了解某个表的结构。
All descriptions lack recovery guidance and error context. When a tool fails (e.g., 'table not found'), agents don't know what to try next. Descriptions should include dependency hints and error recovery paths.
Parameter descriptions lack concrete constraints. E.g., 'limit' parameter in get_enum_values says 'default 50, max 100' inline but should use minItems/maxItems in schema. 'port' in connect_database has no range guidance (valid: 1 - 65535?). 'tableName' accepts 'schema.table_name' format but no regex pattern enforced.
No tool annotations present (readOnlyHint, destructiveHint, idempotentHint). Per current MCP spec, tools should declare whether they modify state or are safe to retry. This helps agents reason about side effects and retries.
Descriptions are often verbose and include implementation details rather than user-centric intent. E.g., connect_database description lists 17 database types inline, better to explain 'Connect to any major SQL or NoSQL database' and let the enum speak. Average is ~200 chars (good) but many are at the high end of LLM-efficient range.
No pagination support for tools that may return large result sets (get_schema, get_enum_values). If a schema has 1000+ tables or a column has 10k+ unique values, the response could exhaust context. Missing: limit, offset/cursor, total_count in responses.
execute_query tool combines SELECT/INSERT/UPDATE/DELETE in one tool. Per composition pattern, this violates single responsibility. Agents cannot selectively grant read-only vs write access. Consider splitting into read_query and write_query or marking write intent explicitly.
No confirmation or dry-run pattern for destructive operations (execute_query with DELETE, connect_database with allowWrite=true). Agents make mistakes, these should support a 'confirm before execute' pattern to prevent data loss.