SQL ServerSAFE
Enterprise MCP server for SQL Server with 20 tools for schema discovery, data operations, and administration.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@connorbritain/mssql-mcp-server) [](https://opensource.org/licenses/MIT)
Enterprise-grade Model Context Protocol server for Microsoft SQL Server.
A production-ready MCP server built for real-world database work: exploring unfamiliar schemas, profiling data shape, validating pipelines in UAT, and moving confidently to production. If you work with SQL Server and want AI tooling that understands enterprise database workflows, this is for you.
Package Tiers
Choose the tier that matches your security requirements. All tiers share the same governance controls, audit logging, and multi-environment support.
Why This Exists
Most SQL + AI demos stop at "generate a query." That's table stakes. Real database work means:
- Navigating massive schemas you didn't design, often with cryptic naming conventions
- Understanding data shape before writing anything
- Working safely in regulated environments where one bad UPDATE can trigger an incident
- Moving fast in UAT so you can validate changes before they hit production
This server is built around those realities. It's stable, secure by default, and designed to make AI assistants genuinely useful on enterprise SQL Server instances.
What's here today
- **Semantic schema di
7526aaed7e95OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mssql-mcp-server -- npx -y @connorbritain/[email protected]
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
@connorbritain/mssql-mcp-core, @types/mssql, @types/node, shx, typescript
├──► client-a-dev (10.0.1.101:1433, SQL auth, full access)
└──► internal-dev (localhost:1433, SQL auth, full access)
- `load-from-credential-manager.ps1`
For enhanced security, load credentials from your platform's native secret store before launching the MCP server. Example scripts are provided in the `examples/` folder:
| Windows | `load-from-credential-manager.ps1` | Windows Credential Manager |
# ... (see examples/load-from-credential-manager.ps1 for full script)
- **Status**: ✅ Implemented – default auth path acquires an Azure AD access token via `InteractiveBrowserCredential` (@MssqlMcp/Node/src/index.ts#109-138, @README.md#118-128).
This folder contains sample templates that demonstrate different ways to wire up credentials and database environments for the MSSQL MCP server. Every file uses **generic placeholders** so you can saf
Gates applied: no_behavioural_pass.
7526aaed7e95full audit observations/trust-audit/mcp-server/connorbritain__sql-server-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7526aaed7e95 | SAFE | B | 89 | first audit |
Questions
What is the SQL Server MCP server?
Enterprise MCP server for SQL Server with 20 tools for schema discovery, data operations, and administration.
Is SQL Server safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does SQL Server need?
No credential environment variables were found in its source, so it appears to need none.
How does SQL Server run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @connorbritain/mssql-mcp-server at 0.7.0.
How current is this page?
The grade is for one exact copy of the source (7526aaed7e95), read on 2026-10-08. The repository is watched and re-audited when it changes.