A Supabase MCP server with Apps SDK widgets for database exploration and SQL execution
This server exposes 4 tools via the mcp-use framework, wrapping Supabase's official MCP server. Tool definitions are present with basic schemas and descriptions, but multiple critical gaps prevent production readiness. All tools have descriptions (10-50 chars, meeting the >10 minimum but falling short of the 50-200 char LLM-optimized baseline). Schemas are present but inconsistently detailed. The server properly uses toolAnnotations (readOnlyHint) to mark all tools as read-only, which is correct. However, parameter descriptions are sparse, error handling is minimal, and tool composition lacks idempotency guarantees. The list-tables tool accepts a 'schemas' parameter with description 'Schemas to include (default: all)' but the code hardcodes ['public'], contradicting the schema. The execute-sql tool lacks any constraint on query syntax (e.g., no enforcement of SELECT-only). The show-table tool constructs SQL dynamically without demonstrating input sanitization. The get-project-url tool has no schema definition visible, only a description, making it difficult to assess parameter handling. Per-tool scores average 48.
Execute read-only SQL queries on your Supabase database
Get the API URL for your Supabase project
List all tables in your Supabase database
Display data from a specific table
execute-sql does not enforce read-only constraint; accepts arbitrary SQL
list-tables schema declares optional 'schemas' parameter but code hardcodes ['public']
Tool descriptions are too brief; lack LLM-optimized context
No output schema documented for any tool
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 47 | - | v1 |
Error responses are generic; do not guide LLM recovery
No idempotency guarantees stated for any tool