Atlas / MCP servers / call518 / PostgreSQL Operations

PostgreSQL OperationsSAFE

mcp/call518/postgresql-operations

🐘 Give AI assistants full PostgreSQL DBA superpowers — 30+ tools for performance analysis, bloat detection, lock/deadlock monitoring, autovacuum & schema inspection. No extensions required. PG 12-18.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
38 38r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/smithery%2Fcall518%2Fmcp-postgresql-ops)

[](https://opensource.org/licenses/MIT) [](https://www.buymeacoffee.com/call518)

[](https://github.com/call518/MCP-PostgreSQL-Ops/actions/workflows/pypi-publish.yml)

Architecture & Internal (DeepWiki)

[](https://deepwiki.com/call518/MCP-PostgreSQL-Ops)

Overview

MCP-PostgreSQL-Ops is a professional MCP server for PostgreSQL database operations, monitoring, and management. Supports PostgreSQL 12-18 with comprehensive database analysis, performance monitoring, and intelligent maintenance recommendations through natural language queries. Most features work independently, but advanced query analysis capabilities are enhanced when pg_stat_statements and (optionally) pg_stat_monitor extensions are installed.

Features

  • ✅ Zero Configuration: Works with PostgreSQL 12-18 out-of-the-box with automatic version detection.
  • ✅ Natural Language: Ask questions like "Show me slow queries" or "Analyze table bloat."
  • ✅ Production Safe: Read-only operations, RD
Read from source at commit 19d303caac1aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-postgresql-ops --env POSTGRES_PASSWORD=${POSTGRES_PASSWORD} --env REMOTE_AUTH_ENABLE=${REMOTE_AUTH_ENABLE} --env REMOTE_SECRET_KEY=${REMOTE_SECRET_KEY} -- uvx mcp-postgresql-ops
claude-desktop
{
  "mcpServers": {
    "mcp-postgresql-ops": {
      "command": "uvx",
      "args": [
        "mcp-postgresql-ops"
      ],
      "env": {
        "POSTGRES_PASSWORD": "${POSTGRES_PASSWORD}",
        "REMOTE_AUTH_ENABLE": "${REMOTE_AUTH_ENABLE}",
        "REMOTE_SECRET_KEY": "${REMOTE_SECRET_KEY}"
      }
    }
  }
}
03

Exposed tools (38)

38 read · 0 write · 0 destructive.

ToolRiskDescription
get_active_connectionsread
get_all_tables_statsread
get_async_io_statusread
get_autovacuum_activityread
get_autovacuum_statusread
get_bgwriter_statsread
get_current_database_inforead
get_database_bloat_overviewread
get_database_conflicts_statsread
get_database_listread
get_database_schema_inforead
get_database_size_inforead
get_database_statsread
get_index_io_statsread
get_index_usage_statsread
get_io_statsread
get_lock_monitoringread
get_per_backend_io_statsread
get_pg_stat_monitor_recent_queriesread
get_pg_stat_statements_top_queriesread
get_postgresql_configread
get_prompt_templateread
get_replication_statusread
get_running_vacuum_operationsread
get_server_inforead
get_table_bloat_analysisread
get_table_io_statsread
get_table_listread
get_table_relationshipsread
get_table_schema_inforead
get_table_size_inforead
get_user_functions_statsread
get_user_listread
get_vacuum_analyze_statsread
get_vacuum_effectiveness_analysisread
get_wait_eventsread
get_wal_statusread
get_wal_summarizer_statusread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 19d303caac1afull audit observations/trust-audit/mcp-server/call518__postgresql-operations.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0719d303caac1aSAFEB89first audit
06

Questions

What is the PostgreSQL Operations MCP server?

🐘 Give AI assistants full PostgreSQL DBA superpowers — 30+ tools for performance analysis, bloat detection, lock/deadlock monitoring, autovacuum & schema inspection. No extensions required. PG 12-18.

What tools does PostgreSQL Operations expose?

38 in total: 38 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is PostgreSQL Operations safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does PostgreSQL Operations need?

It reads POSTGRES_PASSWORD, REMOTE_AUTH_ENABLE and REMOTE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does PostgreSQL Operations run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-postgresql-ops.

How current is this page?

The grade is for one exact copy of the source (19d303caac1a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement