A powerful Model Context Protocol (MCP) server that provides universal SQL database connectivity with intelligent query optimization, schema introspection, and built-in safety features for AI assistants.
The server provides 5 well-named, read-only database tools with clear descriptions and complete input schemas. Naming follows verb_noun conventions (list_*, get_*, execute_*). Descriptions are detailed (150-250 chars) and explain WHEN to use each tool. However, output schemas are not documented, critical for an agent to understand what data structures are returned and what IDs to chain downstream. Error handling is not visible in the provided code, and there are no tool annotations (readOnlyHint, idempotentHint) despite all tools being read-only. The server is well-structured for discovery and query execution but lacks downstream chaining guidance and error recovery patterns.
Execute SELECT queries and retrieve data from databases. Use this tool to run SELECT queries with optional parameters. Supports all query types that return data (SELECT, EXPLAIN, SHOW, etc.). Queries are validated to prevent accidental writes.
Get complete schema information for all configured databases. Returns detailed metadata for all databases, schemas, tables, columns, and relationships. Use this for comprehensive database discovery or when you need schema details across multiple databases.
**CRITICAL FOR SQL WRITING**: Get detailed schema for a specific database. **ALWAYS use this tool before writing SQL queries** to get exact table structures, column names, data types, and relationships for accurate SQL generation.
List all configured databases with identifiers and basic information. Use this tool to discover available databases before exploring schemas or executing queries. Returns database identifiers needed for other tools.
List tables, views, and materialized views in a database schema. Provides quick overview of available database objects with column counts and comments. Use this for discovery before getting detailed schema information.
Output schemas are not documented. The server returns database metadata and query results but does not specify the structure of these responses. Agents cannot predict what fields to extract or what IDs are available for downstream tool calls (e.g., after list_databases, what fields identify a database for use in list_tables?).
No tool annotations present. All 5 tools are read-only (Risk: READ_ONLY marked), but no readOnlyHint annotation is visible in the schema. Tool annotations (readOnlyHint, idempotentHint) are part of the current MCP spec (2026-07-28) and help agents optimize planning and understand safety.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 63 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 42 | - | v1 |
Error handling and recovery guidance not visible. No documentation of what happens if a database_identifier is invalid, if a schema doesn't exist, or if a query fails. Agents need actionable error messages with next steps (e.g., 'Database not found. Call list_databases() to see available options.').
execute_select_statement accepts a 'params' parameter (object type) with no validation or structure guidance. The description mentions 'parameterized queries' but does not explain the expected format, naming convention (named :param vs ? placeholders), or how SQL injection is prevented. This is a security and usability gap.
Result limits not specified. get_all_database_details and list_tables may return many rows. Without pagination or result caps, large datasets could exhaust the context window. Descriptions should state max results and whether pagination is supported.