PostgreSQL OperationsSAFE
🐘 Give AI assistants full PostgreSQL DBA superpowers — 30+ tools for performance analysis, bloat detection, lock/deadlock monitoring, autovacuum & schema inspection. No extensions required. PG 12-18.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/smithery%2Fcall518%2Fmcp-postgresql-ops)
[](https://opensource.org/licenses/MIT) [](https://www.buymeacoffee.com/call518)
[](https://github.com/call518/MCP-PostgreSQL-Ops/actions/workflows/pypi-publish.yml)
Architecture & Internal (DeepWiki)
[](https://deepwiki.com/call518/MCP-PostgreSQL-Ops)
Overview
MCP-PostgreSQL-Ops is a professional MCP server for PostgreSQL database operations, monitoring, and management. Supports PostgreSQL 12-18 with comprehensive database analysis, performance monitoring, and intelligent maintenance recommendations through natural language queries. Most features work independently, but advanced query analysis capabilities are enhanced when pg_stat_statements and (optionally) pg_stat_monitor extensions are installed.
Features
- ✅ Zero Configuration: Works with PostgreSQL 12-18 out-of-the-box with automatic version detection.
- ✅ Natural Language: Ask questions like "Show me slow queries" or "Analyze table bloat."
- ✅ Production Safe: Read-only operations, RD
19d303caac1aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-postgresql-ops --env POSTGRES_PASSWORD=${POSTGRES_PASSWORD} --env REMOTE_AUTH_ENABLE=${REMOTE_AUTH_ENABLE} --env REMOTE_SECRET_KEY=${REMOTE_SECRET_KEY} -- uvx mcp-postgresql-ops{
"mcpServers": {
"mcp-postgresql-ops": {
"command": "uvx",
"args": [
"mcp-postgresql-ops"
],
"env": {
"POSTGRES_PASSWORD": "${POSTGRES_PASSWORD}",
"REMOTE_AUTH_ENABLE": "${REMOTE_AUTH_ENABLE}",
"REMOTE_SECRET_KEY": "${REMOTE_SECRET_KEY}"
}
}
}
}Exposed tools (38)
38 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_active_connections | read | |
get_all_tables_stats | read | |
get_async_io_status | read | |
get_autovacuum_activity | read | |
get_autovacuum_status | read | |
get_bgwriter_stats | read | |
get_current_database_info | read | |
get_database_bloat_overview | read | |
get_database_conflicts_stats | read | |
get_database_list | read | |
get_database_schema_info | read | |
get_database_size_info | read | |
get_database_stats | read | |
get_index_io_stats | read | |
get_index_usage_stats | read | |
get_io_stats | read | |
get_lock_monitoring | read | |
get_per_backend_io_stats | read | |
get_pg_stat_monitor_recent_queries | read | |
get_pg_stat_statements_top_queries | read | |
get_postgresql_config | read | |
get_prompt_template | read | |
get_replication_status | read | |
get_running_vacuum_operations | read | |
get_server_info | read | |
get_table_bloat_analysis | read | |
get_table_io_stats | read | |
get_table_list | read | |
get_table_relationships | read | |
get_table_schema_info | read | |
get_table_size_info | read | |
get_user_functions_stats | read | |
get_user_list | read | |
get_vacuum_analyze_stats | read | |
get_vacuum_effectiveness_analysis | read | |
get_wait_events | read | |
get_wal_status | read | |
get_wal_summarizer_status | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
.gitleaks.toml
.pre-commit-config.yaml
Gates applied: no_behavioural_pass.
19d303caac1afull audit observations/trust-audit/mcp-server/call518__postgresql-operations.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 19d303caac1a | SAFE | B | 89 | first audit |
Questions
What is the PostgreSQL Operations MCP server?
🐘 Give AI assistants full PostgreSQL DBA superpowers — 30+ tools for performance analysis, bloat detection, lock/deadlock monitoring, autovacuum & schema inspection. No extensions required. PG 12-18.
What tools does PostgreSQL Operations expose?
38 in total: 38 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is PostgreSQL Operations safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does PostgreSQL Operations need?
It reads POSTGRES_PASSWORD, REMOTE_AUTH_ENABLE and REMOTE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does PostgreSQL Operations run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-postgresql-ops.
How current is this page?
The grade is for one exact copy of the source (19d303caac1a), read on 2026-10-07. The repository is watched and re-audited when it changes.