MySQLCAUTION
An MCP server provides read-only access to MySQL databases.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mysql-mcp-server)
This MCP server provides read-only access to MySQL databases. It allows you to:
- List available databases
- List tables in a database
- Describe table schemas
- Execute read-only SQL queries
Security Features
- Read-only access: Only SELECT, SHOW, DESCRIBE, and EXPLAIN statements are allowed; file-capable
SELECT INTOandLOAD_FILEforms are rejected - Query validation: Prevents SQL injection and blocks any data modification attempts
- Query timeout: Prevents long-running queries from consuming resources
- Row limit: Prevents excessive data return
- Exact large numbers: BIGINT and DECIMAL values are returned as strings to prevent precision loss
Installation
1. Install using one of these methods:
Install from NPM
# Install globally npm install -g mysql-mcp-server # Or install locally in your project npm install mysql-mcp-server
Build from Source
# Clone the repository git clone https://github.com/dpflucas/mysql-mcp-server.git cd mysql-mcp-server # Install dependencies and build npm install npm run build
2. Configure environment variables
The server requires the following environment variables:
MYSQL_HOST: Database server hostnameMYSQL_PORT: Database server port (default: 3306)MYSQL_USER: Database usernameMYSQL_PASSWORD: Database password (optional, but recommended for secure connections)MYSQL_DATABASE: Default database name (optional)
3. Add to MCP settings
Add the following configuration to your MCP settings file:
If you installed via npm (Option 1):
{
"mcpServers": {
"mysqc084c716d5fdOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mysql-mcp-server --env MYSQL_PASSWORD=${MYSQL_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"mysql-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MYSQL_PASSWORD": "${MYSQL_PASSWORD}"
}
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe_table | read | Show the schema for a specific table |
execute_query | write | Execute a read-only SQL query |
list_databases | read | List all accessible databases on the MySQL server |
list_tables | read | List all tables in a specified database |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
"SELECT LOAD_FILE('/etc/passwd')","SELECT load_file ( '/etc/passwd' )",
.worktreeinclude
@modelcontextprotocol/sdk, mysql2, @types/node, dotenv, typescript
Gates applied: no_behavioural_pass.
c084c716d5fdfull audit observations/trust-audit/mcp-server/dpflucas__mysql-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c084c716d5fd | CAUTION | B | 89 | first audit |
Questions
What is the MySQL MCP server?
An MCP server provides read-only access to MySQL databases.
What tools does MySQL expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MySQL safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does MySQL need?
It reads MYSQL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MySQL run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mysql-mcp-server at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (c084c716d5fd), read on 2026-10-07. The repository is watched and re-audited when it changes.