A universal MCP server for exploring and querying PostgreSQL, MySQL, SQLite, and MongoDB databases
Database Explorer MCP has 3 visible tools (connect_database, disconnect_database, list_connections) with schema definitions and descriptions. However, the server code references 8 tool registration functions (connect, schema, query, stats, optimize, export, erd, search) but only 3 tools are documented in the evaluation input. The visible tools have reasonable descriptions (50-100 chars) and input schemas, but descriptions lack LLM optimization (missing WHEN to use, prerequisites, or dependency hints). The tool names follow verb_noun convention. A critical issue: the descriptions do not explain consequences (e.g., connect_database description omits 'Returns the alias for use in all subsequent operations'), and parameter descriptions are generic. Schemas are present but lack comprehensive validation constraints (e.g., no min/max for port numbers, no pattern validation for aliases). The three visible tools average 65/100; inferred tools from code cannot be scored due to lack of visible definitions.
Connect to a database (PostgreSQL, MySQL, SQLite, or MongoDB). Returns the connection alias for use in subsequent queries.
Disconnect from a database by its alias.
List all active database connections.
Descriptions lack LLM-optimized clarity. 'Connect to a database...' (50 chars) is minimal and omits WHEN to use (before running queries), prerequisites (port must be accessible), or what success looks like (returns alias for downstream use). Baseline A+ descriptions are 50-200 chars and explicitly state these.
Parameter descriptions are minimal or generic. 'Connection alias (default: default)' for alias param lacks context, does it identify the connection? Why not just call it 'connection_id'? 'Database host (default: localhost)' assumes LLMs understand networking defaults. Should state: 'Hostname or IP of the database server (e.g., db.example.com). Defaults to localhost for local dev.'
Port parameter lacks validation constraints. Should specify 'port (1-65535, default: database-specific, PostgreSQL 5432, MySQL 3306, MongoDB 27017)' to guide LLM input.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 55 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Output schema not documented. connect_database description states 'Returns the connection alias for use in subsequent queries' but no schema is visible showing what the response looks like (is it {alias: string}? {status, alias, details}?).
Tools lack error guidance. If connect_database fails (wrong password, host unreachable, port blocked), no error handling text is visible. Rubric requires 'Error responses must tell the LLM what to do next', e.g., 'Connection failed: could not reach db.example.com:5432. Verify the host is accessible and port is open.'
Inferred tools (from registerSchemaTools, registerQueryTools, etc. in src/server.ts) are not documented in the evaluation. Code references at least 8 tool registration functions but only 3 tools provided.
Sensitive parameter handling unclear. password param in connect_database has no guidance about credential security. Rubric mandates: 'Never expose API keys, tokens, passwords, or secrets as tool parameters. Use server-side secret injection.' Password as a direct tool parameter is a security anti-pattern, should accept password via environment variable or secure vault, not as LLM-provided input.
connectionString parameter accepts full URI but guidance is missing on how it overrides individual fields (host, port, user, password). Mutually exclusive or overlapping parameters must state dependencies: 'If connectionString is provided, host, port, user, password are ignored.'