AnalyticDB for MySQLSAFE
AnalyticDB for MySQL MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
AnalyticDB for MySQL MCP Server is a universal interface between AI Agents and AnalyticDB MySQL. It provides two tool groups:
- SQL Tools & Resources (
sqlgroup): Connect directly to ADB MySQL clusters to execute SQL, view execution plans, and browse database metadata. Thesqlgroup is only a tool-group switch;execute_sqlruns in read-only mode by default, and full SQL execution mode requires the additional explicit settingENABLE_SQL_WRITE_TOOLS=true. - OpenAPI Tools (
openapigroup): Manage clusters, whitelists, accounts, networking, monitoring, diagnostics, and audit logs via Alibaba Cloud OpenAPI.
Read-only tools are annotated with ToolAnnotations(readOnlyHint=True) per the MCP protocol, allowing clients to distinguish them from mutating operations.
一、Prerequisites
- Python >= 3.13
- uv (recommended package manager and runner)
- Alibaba Cloud AccessKey (required for OpenAPI tools)
- Optional: ADB MySQL connection credentials (for SQL tools in direct-connection mode)
二、Quick Start
2.0 Choose a Configuration
Choose the tool groups and extra switches for your scenario before copying a client configuration:
769b5d6a6a40OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add adb-mysql-mcp-server --env ADB_MYSQL_PASSWORD=${ADB_MYSQL_PASSWORD} --env ALIBABA_CLOUD_ACCESS_KEY_ID=${ALIBABA_CLOUD_ACCESS_KEY_ID} --env ALIBABA_CLOUD_ACCESS_KEY_SECRET=${ALIBABA_CLOUD_ACCESS_KEY_SECRET} --env ALIBABA_CLOUD_SECURITY_TOKEN=${ALIBABA_CLOUD_SECURITY_TOKEN} -- uvx adb-mysql-mcp-server{
"mcpServers": {
"adb-mysql-mcp-server": {
"command": "uvx",
"args": [
"adb-mysql-mcp-server"
],
"env": {
"ADB_MYSQL_PASSWORD": "${ADB_MYSQL_PASSWORD}",
"ALIBABA_CLOUD_ACCESS_KEY_ID": "${ALIBABA_CLOUD_ACCESS_KEY_ID}",
"ALIBABA_CLOUD_ACCESS_KEY_SECRET": "${ALIBABA_CLOUD_ACCESS_KEY_SECRET}",
"ALIBABA_CLOUD_SECURITY_TOKEN": "${ALIBABA_CLOUD_SECURITY_TOKEN}"
}
}
}
}Exposed tools (34)
26 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_account | write | Create a database account for a cluster. |
describe_accounts | read | List database accounts in a cluster. |
describe_audit_log_records | read | Query SQL audit log records. Requires SQL audit to be enabled on the cluster. |
describe_available_advices | read | Get available optimization advices (index, partition, etc.) for a cluster. |
describe_bad_sql_detection | read | Detect bad SQL queries that may impact cluster stability. |
describe_cluster_access_whitelist | read | Get the IP whitelist configuration of a cluster. |
describe_cluster_net_info | read | Get network connection info of a cluster (VPC/public endpoints, ports). |
describe_controller_detection | write | Run diagnostics on access nodes (Controllers). |
describe_db_cluster_attribute | read | Get detailed attributes of a cluster (spec, status, VPC info, etc.). |
describe_db_cluster_health_status | read | Query the health status of a cluster (connections, disk, nodes, etc.). |
describe_db_cluster_performance | read | Query cluster performance metrics. |
describe_db_cluster_space_summary | read | Get the storage space summary of a cluster (data, index, log sizes). |
describe_db_clusters | read | List ADB MySQL clusters in a region. |
describe_db_resource_group | read | Get resource group configuration of a cluster. |
describe_diagnosis_records | read | Query SQL diagnosis summary records within a time range. |
describe_diagnosis_sql_info | read | Get execution details of a single SQL (plan, runtime info, diagnosis). |
describe_excessive_primary_keys | read | Detect tables with excessive primary key usage that may impact performance. |
describe_executor_detection | write | Run diagnostics on compute nodes (Executors). |
describe_inclined_tables | read | Detect data-skewed tables where data distribution is uneven across nodes. |
describe_oversize_non_partition_table_infos | read | Detect oversized non-partition tables that should consider partitioning. |
describe_sql_patterns | read | Query SQL pattern (template) list sorted by aggregated statistics. |
describe_table_partition_diagnose | read | Diagnose table partitioning issues (skew, too many/few partitions, etc.). |
describe_table_statistics | read | Query table-level statistics (row count, data size, index size, etc.). |
describe_worker_detection | write | Run diagnostics on storage nodes (Workers). |
execute_sql | write | Execute a SQL query on an ADB MySQL cluster. |
get_current_time | read | Get the current time of the MCP Server (provides time context for LLMs). |
get_execution_plan | read | Get the EXPLAIN ANALYZE actual execution plan with runtime statistics. |
get_query_plan | read | Get the EXPLAIN logical execution plan of a SQL query. |
kill_process | destructive | Kill a running query process in the cluster. |
modify_cluster_access_whitelist | write | Modify the IP whitelist of a cluster. |
modify_db_cluster_description | write | Modify the description of a cluster. |
my_tool | read | return x |
tool_a | read | return |
tool_b | read | return |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
kill_process
remote_server = "http://127.0.0.1:8000/sse"
remote_server = "http://127.0.0.1:8000/sse"
base = f"http://127.0.0.1:{self.server.server_port}"f"http://127.0.0.1:{self.server.server_port}"f"http://127.0.0.1:{self.server.server_port}"alibabacloud-adb20211201, alibabacloud-tea-openapi, alibabacloud-tea-util, pymysql
mysql-connector-python, APScheduler, openai, anthropic
pymysql
If the server is bound to a non-loopback host, configure `API_KEY` on the server side and send it from the client side as an HTTP header. In short: `API_KEY` is the server-side token, and `Authorizati
assets/cherry-config.png
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
769b5d6a6a40full audit observations/trust-audit/mcp-server/aliyun__analyticdb-for-mysql.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 769b5d6a6a40 | SAFE | B | 89 | first audit |
Questions
What is the AnalyticDB for MySQL MCP server?
AnalyticDB for MySQL MCP Server
What tools does AnalyticDB for MySQL expose?
34 in total: 26 read-only, 7 that write, and 1 that can delete or overwrite (kill_process). Every one is listed on this page with its risk.
Is AnalyticDB for MySQL safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does AnalyticDB for MySQL need?
It reads ADB_MYSQL_PASSWORD, ALIBABA_CLOUD_ACCESS_KEY_ID, ALIBABA_CLOUD_ACCESS_KEY_SECRET, ALIBABA_CLOUD_SECURITY_TOKEN and API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AnalyticDB for MySQL run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as adb-mysql-mcp-server.
How current is this page?
The grade is for one exact copy of the source (769b5d6a6a40), read on 2026-10-08. The repository is watched and re-audited when it changes.