Local MCP server for secure database queries with Apple Keychain credentials
Server has 5 tools with clear verb-noun naming (list_*, describe_*, query, query_log). All tools have descriptions (avg ~150 chars, within baseline 34-392). Input schemas are present with typed parameters and descriptions. However, output schemas are undocumented, tools return formatted strings rather than structured objects, forcing LLMs to parse unstructured text. Error handling is minimal: no recovery guidance, no categorization of retryable vs fatal errors. Security is strong (credentials via keychain, audit logging, permission checks), but output lacks pagination support and result limits are not exposed in descriptions.
Show the structure of a database table (columns, types, keys).
List all configured database connections with their driver, database, and permission level.
List all tables in a database.
Execute a SQL query on a database connection. The query type is checked against the connection's allowed operations. Permissions can be a preset (read, write, admin) or a custom list of allowed operations (e.g. [select, insert]). Multi-statement queries are blocked. SELECT queries have an automatic row limit.
Show recent query audit log entries.
Output schemas undocumented. All tools return formatted strings (e.g., _format_result returns table text, error messages as plain text). LLMs cannot parse structured output or chain results to downstream tools. LLMs need to know what fields to expect.'
No error recovery guidance. Error responses are bare strings ('ERROR: ...', 'DENIED: ...').
Result limits not exposed in descriptions. query_log has a 'limit' parameter (default 20) but description does not state the maximum or explain pagination. query() has an automatic row limit (per description) but the limit value is not specified.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 72 | 2026-07-28+ | v2 |
No tool annotations. Tools lack readOnlyHint, destructiveHint, or idempotentHint metadata. Per current MCP spec (2026-07-28), tool annotations enable agents to reason about side effects and retry safety.
Parameter descriptions lack format/constraint details. 'connection' param described as 'Name of the database connection to use' but does not explain how to discover valid connection names (call list_connections first).