Atlas / MCP servers / connorbritain / SQL Server

SQL ServerSAFE

mcp/connorbritain/sql-server-6

Enterprise MCP server for SQL Server with 20 tools for schema discovery, data operations, and administration.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@connorbritain/mssql-mcp-server) [](https://opensource.org/licenses/MIT)

Enterprise-grade Model Context Protocol server for Microsoft SQL Server.

A production-ready MCP server built for real-world database work: exploring unfamiliar schemas, profiling data shape, validating pipelines in UAT, and moving confidently to production. If you work with SQL Server and want AI tooling that understands enterprise database workflows, this is for you.

Package Tiers

Choose the tier that matches your security requirements. All tiers share the same governance controls, audit logging, and multi-environment support.

Why This Exists

Most SQL + AI demos stop at "generate a query." That's table stakes. Real database work means:

  • Navigating massive schemas you didn't design, often with cryptic naming conventions
  • Understanding data shape before writing anything
  • Working safely in regulated environments where one bad UPDATE can trigger an incident
  • Moving fast in UAT so you can validate changes before they hit production

This server is built around those realities. It's stable, secure by default, and designed to make AI assistants genuinely useful on enterprise SQL Server instances.

What's here today

  • **Semantic schema di
Read from source at commit 7526aaed7e95OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add mssql-mcp-server -- npx -y @connorbritain/[email protected]
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/node/package.json
@connorbritain/mssql-mcp-core, @types/mssql, @types/node, shx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
DEPLOYMENT.md:315
├──► client-a-dev   (10.0.1.101:1433, SQL auth, full access)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
DEPLOYMENT.md:317
└──► internal-dev   (localhost:1433, SQL auth, full access)
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
GOVERNANCE_ROADMAP.md:47
- `load-from-credential-manager.ps1`
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:282
For enhanced security, load credentials from your platform's native secret store before launching the MCP server. Example scripts are provided in the `examples/` folder:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:286
| Windows | `load-from-credential-manager.ps1` | Windows Credential Manager |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:299
# ... (see examples/load-from-credential-manager.ps1 for full script)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
ROADMAP.md:168
- **Status**: ✅ Implemented – default auth path acquires an Azure AD access token via `InteractiveBrowserCredential` (@MssqlMcp/Node/src/index.ts#109-138, @README.md#118-128).
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
examples/README.md:3
This folder contains sample templates that demonstrate different ways to wire up credentials and database environments for the MSSQL MCP server. Every file uses **generic placeholders** so you can saf
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7526aaed7e95full audit observations/trust-audit/mcp-server/connorbritain__sql-server-6.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087526aaed7e95SAFEB89first audit
05

Questions

What is the SQL Server MCP server?

Enterprise MCP server for SQL Server with 20 tools for schema discovery, data operations, and administration.

Is SQL Server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does SQL Server need?

No credential environment variables were found in its source, so it appears to need none.

How does SQL Server run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @connorbritain/mssql-mcp-server at 0.7.0.

How current is this page?

The grade is for one exact copy of the source (7526aaed7e95), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement