Atlas / MCP servers / anarkh-lee / Universal DB

Universal DBCAUTION

mcp/anarkh-lee/universal-db

通用数据库 MCP 连接器:支持 MySQL、PostgreSQL、Oracle、MongoDB 等 17 种数据库,支持 Claude Desktop、Cursor、Windsurf、VS Code、ChatGPT 等 50+ 平台,用自然语言查询和分析数据

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
9 7r · 0w · 2d
Transport
sse · stdio · streamable-http
License
MIT
Stars
935
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Universal DB MCP

Connect AI to Your Database with Natural Language

A universal database connector implementing the Model Context Protocol (MCP) and HTTP API, enabling AI assistants to query and analyze your databases using natural language. Works with Claude Desktop, Cursor, Windsurf, VS Code, ChatGPT, and 50+ other platforms.

Features • Quick Start • Databases • Docs • Contributing

English | 中文文档

Why Universal DB MCP?

Imagine asking your AI assistant: "Show me the top 10 customers by order value this month" and getting instant results from your database - no SQL writing required. Universal DB MCP makes this possible by bridging AI assistants with your databases

Read from source at commit 60b95fbcbfddOBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add universal-db-mcp --env API_KEYS=${API_KEYS} --env CORS_CREDENTIALS=${CORS_CREDENTIALS} --env DB_PASSWORD=${DB_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "universal-db-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "API_KEYS": "${API_KEYS}",
        "CORS_CREDENTIALS": "${CORS_CREDENTIALS}",
        "DB_PASSWORD": "${DB_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (9)

7 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
clear_cachedestructive清除 Schema 缓存。当数据库结构发生变化(如新增表、修改列)时,可以调用此工具清除缓存。
connect_databaseread连接到数据库。支持动态指定数据库类型和连接参数,无需重启服务。如果当前已有连接,会自动断开旧连接再建立新连接。支持的数据库类型:mysql, postgres, redis, oracle, dm, sqlserver, mongodb, sqlite, kingbase, gaussdb, oceanbase, tidb, clickhouse, polardb, vastbase, highgo, goldendb。
disconnect_databaseread断开当前数据库连接。断开后需要重新调用 connect_database 才能执行查询。
execute_querydestructive执行 SQL 查询或数据库命令。支持 SELECT、JOIN、聚合等查询操作。如果启用了写入模式,也可以执行 INSERT、UPDATE、DELETE 等操作。
get_connection_statusread获取当前数据库连接状态。返回是否已连接、数据库类型、地址、数据库名、权限模式等信息。
get_enum_valuesread获取指定列的所有唯一值。用于了解 status、type、category 等枚举类型列的所有可能值,帮助生成准确的 WHERE 条件。例如:获取 orders.status 列的所有状态值(pending, shipped, delivered 等)。
get_sample_dataread获取表的示例数据(已自动脱敏)。用于了解数据格式,如日期格式(2024-01-01 vs 20240101)、ID格式(UUID vs 自增)、金额精度等。敏感数据(手机号、邮箱、身份证等)会自动脱敏保护隐私。
get_schemaread获取数据库结构信息,包括所有 Schema 中用户可访问的表名、列名、数据类型、主键、索引等元数据。在执行查询前调用此工具可以帮助理解数据库结构。结果会被缓存以提高性能。
get_table_inforead获取指定表的详细信息,包括列定义、索引、预估行数等。用于深入了解某个表的结构。
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (21)

MEDIUMInventory / provenance · inv.binary · CWE-1104
universal-db-mcp-0.1.0.tgz
universal-db-mcp-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_cache, execute_query
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
docker/.env.docker.example
.env.docker.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
serverless/aliyun-fc/index.js:6
const { createHttpServer } = require('../../dist/http/server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
serverless/aliyun-fc/index.js:7
const { loadConfig } = require('../../dist/utils/config-loader.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
serverless/aws-lambda/index.js:6
const { createHttpServer } = require('../../dist/http/server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
serverless/aws-lambda/index.js:7
const { loadConfig } = require('../../dist/utils/config-loader.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
serverless/tencent-scf/index.js:6
const { createHttpServer } = require('../../dist/http/server.js');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deployment/https-domain.md:86
proxy_pass http://127.0.0.1:3001;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/development/implementation.md:263
# 📍 Server URL: http://0.0.0.0:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/development/implementation.zh-CN.md:263
# 📍 Server URL: http://0.0.0.0:3000
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@clickhouse/client, @fastify/cors, @fastify/rate-limit, @modelcontextprotocol/sdk, better-sqlite3, commander, dotenv, fastify
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/operations/guide.md:200
cat /opt/universal-db-mcp/.env
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/operations/troubleshooting.md:175
cat .env
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/databases/tidb.md:23
curl --proto '=https' --tlsv1.2 -sSf https://tiup-mirrors.pingcap.com/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/deployment/cloud/huaweicloud.md:1002
curl -fsSL https://get.docker.com | sudo sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/http-api/DEPLOYMENT.md:633
curl -L https://fly.io/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/http-api/DEPLOYMENT.zh-CN.md:615
curl -L https://fly.io/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/http-api/API_REFERENCE.md:138
curl -X POST "http://localhost:3000/sse/message?sessionId=your-session-id" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/http-api/API_REFERENCE.zh-CN.md:138
curl -X POST "http://localhost:3000/sse/message?sessionId=your-session-id" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/logo1.png
assets/logo1.png
Why it matters. 1056868 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 60b95fbcbfddfull audit observations/trust-audit/mcp-server/anarkh-lee__universal-db.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2660b95fbcbfddCAUTIONB85first audit
06

Questions

What is the Universal DB MCP server?

通用数据库 MCP 连接器:支持 MySQL、PostgreSQL、Oracle、MongoDB 等 17 种数据库,支持 Claude Desktop、Cursor、Windsurf、VS Code、ChatGPT 等 50+ 平台,用自然语言查询和分析数据

What tools does Universal DB expose?

9 in total: 7 read-only, 0 that write, and 2 that can delete or overwrite (clear_cache, execute_query). Every one is listed on this page with its risk.

Is Universal DB safe to connect to an agent?

With care. The audit graded it B (85/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Universal DB need?

It reads API_KEYS, CORS_CREDENTIALS and DB_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Universal DB run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as universal-db-mcp at 2.14.0.

How current is this page?

The grade is for one exact copy of the source (60b95fbcbfdd), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement