IoTDBSAFE
Apache IoTDB MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
Overview
A Model Context Protocol (MCP) server implementation that provides database interaction and business intelligence capabilities through IoTDB. This server enables running SQL queries and interacting with IoTDB using different SQL dialects (Tree Model and Table Model).
Components
Resources
The server doesn't expose any resources.
Prompts
The server doesn't provide any prompts.
Permission Model
IoTDB MCP permissions are advisory by default. The server reports the required permission, risk level, and confirmation parameter for SQL actions, while the host agent system owns user approval. Use inspect_sql_permission before executing DDL/DML or destructive SQL when the tool is available.
Long-running hosted agents can provide full-permission defaults with environment variables such as IOTDB_SQL_DRIVER_MODE=full and TIMESEEK_MCP_PERMISSION_ENFORCEMENT=advisory. Set TIMESEEK_MCP_PERMISSION_ENFORCEMENT=strict only when the MCP server itself should hard-block disallowed operations.
Session policy changes are bounded by a deployment policy frozen at startup (process environment > MCP configuration > defaults). Narrowing applies immediately; widening within that ceiling requires out-of-band administrator approval by default. IOTDB_SESSION_POLICY_APPROVAL_MODE=allow explicitly permits in-ceiling widening without approval. Neither setting allows tools to change enforcement switches, SQL classification prefixes, or the deployment ceiling. Reset and replace follow the same rules. See session policy administration for configuration, approval commands, and the required host isolation.
Tools
The server offers different tools for IoTDB Tree Model and Table Model. You can choose between them by setting the "IOTDBSQLDIALECT" configuration to either "tree" or "table".
Dialect-specific identifier semantics:
- Tree dialect:
FROMtargets use explici
bb8ebdbf8981OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add iotdb-mcp-server -- uvx iotdb-mcp-server
{
"mcpServers": {
"iotdb-mcp-server": {
"command": "uvx",
"args": [
"iotdb-mcp-server"
]
}
}
}Exposed tools (58)
25 read · 27 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
alter_table_ddl | write | Execute table-model ALTER TABLE DDL. |
alter_timeseries_ddl | write | Execute tree-model ALTER TIMESERIES DDL. |
cleanup_result_store | write | Run TTL and quota cleanup for ResultStore entries. |
connect_iotdb_target | write | Authenticate once and publish only after success. |
count_devices | read | Count devices under a tree path pattern. |
count_nodes | read | Count nodes under a tree path. |
count_timeseries | read | Count timeseries under a tree path pattern. |
create_database | write | Create a database/storage group in the selected IoTDB target. |
create_table_ddl | write | Execute table-model CREATE TABLE DDL. |
create_timeseries_batch_ddl | write | Execute a batch of tree-model CREATE TIMESERIES DDL in one session pipeline. |
create_timeseries_ddl | write | Execute tree-model CREATE TIMESERIES DDL. |
delete_result | destructive | Delete one cached ResultStore result. |
describe_iotdb_target | read | Describe one IoTDB target selected by id or selector fields. |
describe_table | read | Describe schema for a table in current table-model database. |
drop_database | destructive | Drop a database/storage group in the selected IoTDB target. |
drop_table_ddl | destructive | Execute table-model DROP TABLE DDL (destructive). |
drop_timeseries_ddl | destructive | Execute tree-model DROP/DELETE TIMESERIES DDL (destructive). |
execute_udf_query | write | Execute one read-only IoTDB UDF SELECT built from validated inputs. |
explain_query | write | Execute EXPLAIN for one statement against the selected IoTDB target. |
export_query | write | Execute one tree-dialect read query and export its result set. |
export_table_query | write | Execute one table-dialect read query and export its result set. |
export_udf_query | write | Execute one read-only IoTDB UDF SELECT and export the result set. |
get_iotdb_session_policy | read | Inspect effective IoTDB MCP permissions for this running session. |
inspect_sql_permission | read | Inspect SQL permission, risk, and approval requirements without executing it. |
list_child_nodes | read | List child nodes under a tree path. |
list_child_paths | read | List child paths under a tree path. |
list_databases | read | List databases in the selected IoTDB target. |
list_devices | read | List devices under a tree path pattern. |
list_iotdb_targets | read | List registered IoTDB targets with redacted credentials. |
list_result_store | read | List ResultStore entries for the current session by default. |
list_tables | read | List all tables in current table-model database. |
list_timeseries | read | List timeseries under a tree path pattern. |
list_udf_functions | read | List IoTDB functions/UDFs visible to the selected target via SHOW FUNCTIONS. |
metadata_query | write | Execute metadata SQL against the selected IoTDB target. |
model_command | write | Execute AINode model-management command SQL. |
model_inference | write | Execute Tree-dialect AINode inference SQL. |
model_query | write | Execute AINode model-query SQL against the selected IoTDB target. |
prepare_iotdb_target | write | Create a credential-free, non-routable target candidate. |
prepare_model_inference_request | read | Build and validate Tree-dialect AINode CALL INFERENCE SQL. |
prepare_udf_query | read | Build a conservative read-only SQL plan for invoking an IoTDB UDF. |
read_query | write | Execute one table-dialect read query and return rows. |
read_result_page | read | Read one page from a previously returned ResultStore result_id. |
read_result_pages | read | Read multiple ResultStore pages in one MCP call. |
register_iotdb_target | read | Compatibility entry point that verifies credentials before registration. |
reload_iotdb_targets | read | Reload IoTDB targets from env, a targets file, or an explicit JSON string. |
remember_iotdb_target_credential | read | Record the selected target |
remove_iotdb_target | destructive | Remove an IoTDB target from this running MCP process. |
reset_iotdb_session_policy | destructive | Reset overrides; any resulting widening requires the same approval as set. |
select_query | write | Execute one tree-dialect read query and return rows. |
set_default_iotdb_target | write | Set the default IoTDB target for this running MCP process. |
set_iotdb_session_policy | write | |
sql_driver_policy | read | Show current sql_driver policy and statement whitelists. |
sql_execute | write | Execute exactly one SQL statement on the selected IoTDB target. |
sql_executor_batch | write | Execute many readonly SQL statements in parallel and store each result. |
ttl_command | write | Execute TTL command SQL. |
ttl_query | write | Execute TTL query SQL. |
use_database | read | Switch current database in a table-model IoTDB target. |
write_query | write | Execute exactly one write statement on the selected IoTDB target. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (6)
delete_result, drop_database, drop_table_ddl, drop_timeseries_ddl, remove_iotdb_target, reset_iotdb_session_policy
.asf.yaml
长期托管 agent 可以通过环境变量提供 full permission 默认值,例如
- 不把自然语言“用户已同意”、普通确认布尔值或 agent full permission 当成人工审批证明。
## 与 agent full permission 的关系
宿主的 full permission 不会自动改变服务端审批模式。人工审批流程应由宿主在独立权限域
Gates applied: no_behavioural_pass.
bb8ebdbf8981full audit observations/trust-audit/mcp-server/apache__iotdb.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | bb8ebdbf8981 | SAFE | B | 89 | first audit |
Questions
What is the IoTDB MCP server?
Apache IoTDB MCP Server
What tools does IoTDB expose?
58 in total: 25 read-only, 27 that write, and 6 that can delete or overwrite (delete_result, drop_database, drop_table_ddl, drop_timeseries_ddl, remove_iotdb_target). Every one is listed on this page with its risk.
Is IoTDB safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does IoTDB need?
No credential environment variables were found in its source, so it appears to need none.
How does IoTDB run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as iotdb-mcp-server.
How current is this page?
The grade is for one exact copy of the source (bb8ebdbf8981), read on 2026-10-08. The repository is watched and re-audited when it changes.