Atlas / MCP servers / donghao1393 / Dbutils

DbutilsSAFE

mcp/donghao1393/dbutils

数读 是一件可以让你的大模型安全连接到数据库的MCP工具。| DButils is an all-in-one MCP service that enables your AI to do data analysis by harnessing versatile types of database (sqlite, mysql, postgres, and more) within a unified configuration of multiple connections in a secured way (like SSL and controlled write access).

Verdict
SAFE
Grade
B
Trust score
85 /100
Exposed tools
8 5r · 2w · 1d
Transport
stdio
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/donghao1393/mcp-dbutils/actions) [](https://github.com/donghao1393/mcp-dbutils/actions) [](https://sonarcloud.io/dashboard?id=donghao1393_mcp-dbutils)

[](https://pypi.org/project/mcp-dbutils/) [](https://pypi.org/project/mcp-dbutils/) [](https://smithery.ai/server/@donghao1393/mcp-dbutils)

[](https://www.python.org/) [](LICENSE) [](https://github.com/donghao1393/mcp-dbutils/stargazers)

English | Français | Español | العربية | Русский | 文档导航

简介

MCP Database Utilities 是一个多功能的 MCP 服务,它使您的 AI 能够通过统一的连接配置安全地访问各种类型的数据库(SQLite、MySQL、PostgreSQL 等)进行数据分析。

您可以将其视为 AI 系统和数据库之间的安全桥梁,允许 AI 在不直接访问数据库或冒数据修改风险的情况下读取和分析您的数据。

核心特性

  • 安全优先:严格只读操作,无直接数据库访问,隔离连接,按需连接,自动超时
  • 隐私保障:本地处理,最小数据暴露,凭证保护,敏感数据屏蔽
  • 多数据库支持:使用相同的接口连接 SQLite、MySQL、PostgreSQL
  • 简单配置:所有数据库连接使用单个 YAML 文件
  • 高级功能:表格浏览、架构分析和查询执行
🔒 安全说明:MCP 数据库工具采用安全优先的架构设计,非常适合注重数据保护的企业、初创公司和个人用户。详细了解我们的安全架构。

快速入门

我们提供了多种安装方式,包括 uvx、Docker 和 Smithery。详细的安装和配置步骤请参阅[安装指南](

Read from source at commit fc6ab07406c1OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-dbutils -- uvx mcp-dbutils
claude-desktop
{
  "mcpServers": {
    "mcp-dbutils": {
      "command": "uvx",
      "args": [
        "mcp-dbutils"
      ]
    }
  }
}
03

Exposed tools (8)

5 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
dbutils-describe-tablereadProvides detailed information about a table
dbutils-execute-writedestructiveCAUTION: This tool executes data modification operations (INSERT, UPDATE, DELETE) on the specified database. It requires explicit configuration and confirmation. Only available for connections with
dbutils-explain-queryreadGet execution plan for a SQL query
dbutils-get-audit-logswriteRetrieves audit logs for database write operations. Shows who performed what operations, when, and with what results. Useful for security monitoring, compliance, and troubleshooting.
dbutils-list-tablesreadList all available tables in the specified database connection
dbutils-run-querywriteExecute read-only SQL query on database connection
queryread执行只读SQL查询
test-toolreadTest tool
04

Trust audit

SAFEgrade B · trust 85/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
dbutils-execute-write
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc
.coveragerc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_mysql.py:33
schema = eval(schema_str)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_mysql.py:51
result = eval(result_str)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_mysql.py:60
result = eval(result_str)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_mysql_handler_extended.py:191
result = eval(result_str)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_mysql_handler_extended.py:201
result = eval(result_str)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
.github/workflows/issue-translator.yml:15
CUSTOM_BOT_NOTE: Bot检测到issue内容不是英文,自动翻译如下。Bot detected the issue body's language is not English, translate it automatically. 👯👭🏻🧑🤝🧑👫🧑🏿🤝🧑🏻👩🏾🤝👨🏿👬🏿
LOWPrompt injection · review.misleading_scope · CWE-94, CWE-1427
README.md
严格只读操作,无直接数据库访问
Why it matters. The package description claims strictly read-only operations, but the toolset includes dbutils-execute-write which performs INSERT, UPDATE, and DELETE operations, a scope the description does not admit.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/ar/installation-platform-specific.md:98
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/ar/installation-platform-specific.md:171
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/ar/installation.md:37
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/en/installation-platform-specific.md:22
curl -sSf https://raw.githubusercontent.com/astral-sh/uv/main/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/en/installation-platform-specific.md:114
curl -sSf https://raw.githubusercontent.com/astral-sh/uv/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fc6ab07406c1full audit observations/trust-audit/mcp-server/donghao1393__dbutils.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fc6ab07406c1SAFEB85first audit
06

Questions

What is the Dbutils MCP server?

数读 是一件可以让你的大模型安全连接到数据库的MCP工具。| DButils is an all-in-one MCP service that enables your AI to do data analysis by harnessing versatile types of database (sqlite, mysql, postgres, and more) within a unified configuration of multiple connections in a secured way (like SSL and controlled write access).

What tools does Dbutils expose?

8 in total: 5 read-only, 2 that write, and 1 that can delete or overwrite (dbutils-execute-write). Every one is listed on this page with its risk.

Is Dbutils safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (85/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Dbutils need?

No credential environment variables were found in its source, so it appears to need none.

How does Dbutils run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-dbutils.

How current is this page?

The grade is for one exact copy of the source (fc6ab07406c1), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement