Remote PostgreSQL DatabaseBLOCK
Template for a remote MCP server with GitHub OAuth - following best practices for building MCP servers so you can take this as a starting point for any MCP server you want to build!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This is a Model Context Protocol (MCP) server that enables you to chat with your PostgreSQL database, deployable as a remote MCP server with GitHub OAuth through Cloudflare. This is production ready MCP.
Key Features
- 🗄️ Database Integration with Lifespan: Direct PostgreSQL database connection for all MCP tool calls
- 🛠️ Modular, Single Purpose Tools: Following best practices around MCP tools and their descriptions
- 🔐 Role-Based Access: GitHub username-based permissions for database write operations
- 📊 Schema Discovery: Automatic table and column information retrieval
- 🛡️ SQL Injection Protection: Built-in validation and sanitization
- 📈 Monitoring: Optional Sentry integration for production monitoring
- ☁️ Cloud Native: Powered by Cloudflare Workers for global scale
Modular Architecture
This MCP server uses a clean, modular architecture that makes it easy to extend and maintain:
- `src/tools/` - Individual tool implementations in separate files
- `registerAllTools()` - Centralized tool registration system
- Extensible Design - Add new tools by creating files in
tools/and registering them
This architecture allows you to easily add new database operations, external API integrations, or any other MCP tools while keeping the codebase organized and maintainable.
Transport Protocols
This MCP server supports both modern and legacy transport protocols:
- `/mcp` - Streamable HTTP (recommended): Uses a single endpoint with bidirectional communication, automatic connection upgrades, and better resilience for network interruptions
- `/sse` - Server-Sent Events (legacy): Uses separate endpoints for requests/responses, maintained for backward compatibility
For new implementations, use the /mcp endpoint as it provides better performance and r
6422d048b680OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add remote-mcp-github-oauth -- npx -y [email protected]
{
"mcpServers": {
"remote-mcp-github-oauth": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (4)
2 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
calculate | read | |
executeDatabase | write | Execute any SQL statement against the PostgreSQL database, including INSERT, UPDATE, DELETE, and DDL operations. This tool is restricted to specific GitHub users and can perform write transactions. **USE WITH CAUTION** - this can modify or delete data. |
listTables | read | Get a list of all tables in the database along with their column information. Use this first to understand the database structure before querying. |
queryDatabase | write | Execute a read-only SQL query against the PostgreSQL database. This tool only allows SELECT statements and other read operations. All authenticated users can use this tool. |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
echo "DATABASE_URL=postgresql://mcp_user:mcp_password@localhost:5432/mcp_database"
- **Local**: `postgresql://myuser:mypass@localhost:5432/mydb`
- **Supabase**: `postgresql://postgres:[email protected]:5432/postgres`
DATABASE_URL: 'postgresql://test:test@localhost:5432/test',
.dev.vars.example
import type { Props } from '../../src/types'import type { McpResponse } from '../../src/types'vi.mock('../../src/database/connection', () => ({vi.mock('../../src/database/utils', () => ({import { validateSqlQuery, isWriteOperation, formatDatabaseError } from '../../../src/database/security'const oauthReqInfo = JSON.parse(atob(c.req.query("state") as string)) as AuthRequest;const jsonString = atob(encoded);
const payload = atob(base64Payload); // Assuming payload is base64 encoded JSON string
atob(data: string): string;
declare function atob(data: string): string;
@cloudflare/workers-oauth-provider, @sentry/cloudflare, agents, hono, just-pick, octokit, postgres, workers-mcp
Gates applied: no_behavioural_pass.
6422d048b680full audit observations/trust-audit/mcp-server/coleam00__remote-postgresql-database.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 6422d048b680 | BLOCK | D | 60 | first audit |
Questions
What is the Remote PostgreSQL Database MCP server?
Template for a remote MCP server with GitHub OAuth - following best practices for building MCP servers so you can take this as a starting point for any MCP server you want to build!
What tools does Remote PostgreSQL Database expose?
4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Remote PostgreSQL Database safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Remote PostgreSQL Database need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (6422d048b680), read on 2026-10-05. The repository is watched and re-audited when it changes.