Atlas / MCP servers / apache / IoTDB

IoTDBSAFE

mcp/apache/iotdb

Apache IoTDB MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
58 25r · 27w · 6d
Transport
stdio
License
Apache-2.0
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

Overview

A Model Context Protocol (MCP) server implementation that provides database interaction and business intelligence capabilities through IoTDB. This server enables running SQL queries and interacting with IoTDB using different SQL dialects (Tree Model and Table Model).

Components

Resources

The server doesn't expose any resources.

Prompts

The server doesn't provide any prompts.

Permission Model

IoTDB MCP permissions are advisory by default. The server reports the required permission, risk level, and confirmation parameter for SQL actions, while the host agent system owns user approval. Use inspect_sql_permission before executing DDL/DML or destructive SQL when the tool is available.

Long-running hosted agents can provide full-permission defaults with environment variables such as IOTDB_SQL_DRIVER_MODE=full and TIMESEEK_MCP_PERMISSION_ENFORCEMENT=advisory. Set TIMESEEK_MCP_PERMISSION_ENFORCEMENT=strict only when the MCP server itself should hard-block disallowed operations.

Session policy changes are bounded by a deployment policy frozen at startup (process environment > MCP configuration > defaults). Narrowing applies immediately; widening within that ceiling requires out-of-band administrator approval by default. IOTDB_SESSION_POLICY_APPROVAL_MODE=allow explicitly permits in-ceiling widening without approval. Neither setting allows tools to change enforcement switches, SQL classification prefixes, or the deployment ceiling. Reset and replace follow the same rules. See session policy administration for configuration, approval commands, and the required host isolation.

Tools

The server offers different tools for IoTDB Tree Model and Table Model. You can choose between them by setting the "IOTDBSQLDIALECT" configuration to either "tree" or "table".

Dialect-specific identifier semantics:

  • Tree dialect:
  • FROM targets use explici
Read from source at commit bb8ebdbf8981OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add iotdb-mcp-server -- uvx iotdb-mcp-server
claude-desktop
{
  "mcpServers": {
    "iotdb-mcp-server": {
      "command": "uvx",
      "args": [
        "iotdb-mcp-server"
      ]
    }
  }
}
03

Exposed tools (58)

25 read · 27 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
alter_table_ddlwriteExecute table-model ALTER TABLE DDL.
alter_timeseries_ddlwriteExecute tree-model ALTER TIMESERIES DDL.
cleanup_result_storewriteRun TTL and quota cleanup for ResultStore entries.
connect_iotdb_targetwriteAuthenticate once and publish only after success.
count_devicesreadCount devices under a tree path pattern.
count_nodesreadCount nodes under a tree path.
count_timeseriesreadCount timeseries under a tree path pattern.
create_databasewriteCreate a database/storage group in the selected IoTDB target.
create_table_ddlwriteExecute table-model CREATE TABLE DDL.
create_timeseries_batch_ddlwriteExecute a batch of tree-model CREATE TIMESERIES DDL in one session pipeline.
create_timeseries_ddlwriteExecute tree-model CREATE TIMESERIES DDL.
delete_resultdestructiveDelete one cached ResultStore result.
describe_iotdb_targetreadDescribe one IoTDB target selected by id or selector fields.
describe_tablereadDescribe schema for a table in current table-model database.
drop_databasedestructiveDrop a database/storage group in the selected IoTDB target.
drop_table_ddldestructiveExecute table-model DROP TABLE DDL (destructive).
drop_timeseries_ddldestructiveExecute tree-model DROP/DELETE TIMESERIES DDL (destructive).
execute_udf_querywriteExecute one read-only IoTDB UDF SELECT built from validated inputs.
explain_querywriteExecute EXPLAIN for one statement against the selected IoTDB target.
export_querywriteExecute one tree-dialect read query and export its result set.
export_table_querywriteExecute one table-dialect read query and export its result set.
export_udf_querywriteExecute one read-only IoTDB UDF SELECT and export the result set.
get_iotdb_session_policyreadInspect effective IoTDB MCP permissions for this running session.
inspect_sql_permissionreadInspect SQL permission, risk, and approval requirements without executing it.
list_child_nodesreadList child nodes under a tree path.
list_child_pathsreadList child paths under a tree path.
list_databasesreadList databases in the selected IoTDB target.
list_devicesreadList devices under a tree path pattern.
list_iotdb_targetsreadList registered IoTDB targets with redacted credentials.
list_result_storereadList ResultStore entries for the current session by default.
list_tablesreadList all tables in current table-model database.
list_timeseriesreadList timeseries under a tree path pattern.
list_udf_functionsreadList IoTDB functions/UDFs visible to the selected target via SHOW FUNCTIONS.
metadata_querywriteExecute metadata SQL against the selected IoTDB target.
model_commandwriteExecute AINode model-management command SQL.
model_inferencewriteExecute Tree-dialect AINode inference SQL.
model_querywriteExecute AINode model-query SQL against the selected IoTDB target.
prepare_iotdb_targetwriteCreate a credential-free, non-routable target candidate.
prepare_model_inference_requestreadBuild and validate Tree-dialect AINode CALL INFERENCE SQL.
prepare_udf_queryreadBuild a conservative read-only SQL plan for invoking an IoTDB UDF.
read_querywriteExecute one table-dialect read query and return rows.
read_result_pagereadRead one page from a previously returned ResultStore result_id.
read_result_pagesreadRead multiple ResultStore pages in one MCP call.
register_iotdb_targetreadCompatibility entry point that verifies credentials before registration.
reload_iotdb_targetsreadReload IoTDB targets from env, a targets file, or an explicit JSON string.
remember_iotdb_target_credentialreadRecord the selected target
remove_iotdb_targetdestructiveRemove an IoTDB target from this running MCP process.
reset_iotdb_session_policydestructiveReset overrides; any resulting widening requires the same approval as set.
select_querywriteExecute one tree-dialect read query and return rows.
set_default_iotdb_targetwriteSet the default IoTDB target for this running MCP process.
set_iotdb_session_policywrite
sql_driver_policyreadShow current sql_driver policy and statement whitelists.
sql_executewriteExecute exactly one SQL statement on the selected IoTDB target.
sql_executor_batchwriteExecute many readonly SQL statements in parallel and store each result.
ttl_commandwriteExecute TTL command SQL.
ttl_querywriteExecute TTL query SQL.
use_databasereadSwitch current database in a table-model IoTDB target.
write_querywriteExecute exactly one write statement on the selected IoTDB target.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (6)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_result, drop_database, drop_table_ddl, drop_timeseries_ddl, remove_iotdb_target, reset_iotdb_session_policy
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.asf.yaml
.asf.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README-zh.md:25
长期托管 agent 可以通过环境变量提供 full permission 默认值,例如
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/iotdb-threat-model-proposal.md:78
- 不把自然语言“用户已同意”、普通确认布尔值或 agent full permission 当成人工审批证明。
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/session-policy-security.md:86
## 与 agent full permission 的关系
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/session-policy-security.md:88
宿主的 full permission 不会自动改变服务端审批模式。人工审批流程应由宿主在独立权限域

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha bb8ebdbf8981full audit observations/trust-audit/mcp-server/apache__iotdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08bb8ebdbf8981SAFEB89first audit
06

Questions

What is the IoTDB MCP server?

Apache IoTDB MCP Server

What tools does IoTDB expose?

58 in total: 25 read-only, 27 that write, and 6 that can delete or overwrite (delete_result, drop_database, drop_table_ddl, drop_timeseries_ddl, remove_iotdb_target). Every one is listed on this page with its risk.

Is IoTDB safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does IoTDB need?

No credential environment variables were found in its source, so it appears to need none.

How does IoTDB run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as iotdb-mcp-server.

How current is this page?

The grade is for one exact copy of the source (bb8ebdbf8981), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement