Atlas / MCP servers / coleam00 / Remote PostgreSQL Database

Remote PostgreSQL DatabaseBLOCK

mcp/coleam00/remote-postgresql-database

Template for a remote MCP server with GitHub OAuth - following best practices for building MCP servers so you can take this as a starting point for any MCP server you want to build!

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
4 2r · 2w · 0d
Transport
—
License
MIT
Stars
300
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This is a Model Context Protocol (MCP) server that enables you to chat with your PostgreSQL database, deployable as a remote MCP server with GitHub OAuth through Cloudflare. This is production ready MCP.

Key Features

  • 🗄️ Database Integration with Lifespan: Direct PostgreSQL database connection for all MCP tool calls
  • 🛠️ Modular, Single Purpose Tools: Following best practices around MCP tools and their descriptions
  • 🔐 Role-Based Access: GitHub username-based permissions for database write operations
  • 📊 Schema Discovery: Automatic table and column information retrieval
  • 🛡️ SQL Injection Protection: Built-in validation and sanitization
  • 📈 Monitoring: Optional Sentry integration for production monitoring
  • ☁️ Cloud Native: Powered by Cloudflare Workers for global scale

Modular Architecture

This MCP server uses a clean, modular architecture that makes it easy to extend and maintain:

  • `src/tools/` - Individual tool implementations in separate files
  • `registerAllTools()` - Centralized tool registration system
  • Extensible Design - Add new tools by creating files in tools/ and registering them

This architecture allows you to easily add new database operations, external API integrations, or any other MCP tools while keeping the codebase organized and maintainable.

Transport Protocols

This MCP server supports both modern and legacy transport protocols:

  • `/mcp` - Streamable HTTP (recommended): Uses a single endpoint with bidirectional communication, automatic connection upgrades, and better resilience for network interruptions
  • `/sse` - Server-Sent Events (legacy): Uses separate endpoints for requests/responses, maintained for backward compatibility

For new implementations, use the /mcp endpoint as it provides better performance and r

Read from source at commit 6422d048b680OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add remote-mcp-github-oauth -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "remote-mcp-github-oauth": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (4)

2 read · 2 write · 0 destructive.

ToolRiskDescription
calculateread
executeDatabasewriteExecute any SQL statement against the PostgreSQL database, including INSERT, UPDATE, DELETE, and DDL operations. This tool is restricted to specific GitHub users and can perform write transactions. **USE WITH CAUTION** - this can modify or delete data.
listTablesreadGet a list of all tables in the database along with their column information. Use this first to understand the database structure before querying.
queryDatabasewriteExecute a read-only SQL query against the PostgreSQL database. This tool only allows SELECT statements and other read operations. All authenticated users can use this tool.
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
worker-configuration.d.ts:2231
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
worker-configuration.d.ts:6229
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
setup-database.sh:59
echo "DATABASE_URL=postgresql://mcp_user:mcp_password@localhost:5432/mcp_database"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:145
- **Local**: `postgresql://myuser:mypass@localhost:5432/mydb`
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:146
- **Supabase**: `postgresql://postgres:[email protected]:5432/postgres`
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/mocks/oauth.mock.ts:45
DATABASE_URL: 'postgresql://test:test@localhost:5432/test',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/auth.fixtures.ts:1
import type { Props } from '../../src/types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/mcp.fixtures.ts:1
import type { McpResponse } from '../../src/types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/mocks/database.mock.ts:18
vi.mock('../../src/database/connection', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/mocks/database.mock.ts:24
vi.mock('../../src/database/utils', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/database/security.test.ts:2
import { validateSqlQuery, isWriteOperation, formatDatabaseError } from '../../../src/database/security'
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/auth/github-handler.ts:80
const oauthReqInfo = JSON.parse(atob(c.req.query("state") as string)) as AuthRequest;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/auth/oauth-utils.ts:41
const jsonString = atob(encoded);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/auth/oauth-utils.ts:137
const payload = atob(base64Payload); // Assuming payload is base64 encoded JSON string
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
worker-configuration.d.ts:215
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
worker-configuration.d.ts:301
declare function atob(data: string): string;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cloudflare/workers-oauth-provider, @sentry/cloudflare, agents, hono, just-pick, octokit, postgres, workers-mcp
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 6422d048b680full audit observations/trust-audit/mcp-server/coleam00__remote-postgresql-database.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-056422d048b680BLOCKD60first audit
06

Questions

What is the Remote PostgreSQL Database MCP server?

Template for a remote MCP server with GitHub OAuth - following best practices for building MCP servers so you can take this as a starting point for any MCP server you want to build!

What tools does Remote PostgreSQL Database expose?

4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Remote PostgreSQL Database safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Remote PostgreSQL Database need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (6422d048b680), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement