Atlas / MCP servers / dpflucas / MySQL

MySQLCAUTION

mcp/dpflucas/mysql-3

An MCP server provides read-only access to MySQL databases.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
4 3r · 1w · 0d
Transport
stdio
License
MIT
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mysql-mcp-server)

This MCP server provides read-only access to MySQL databases. It allows you to:

  • List available databases
  • List tables in a database
  • Describe table schemas
  • Execute read-only SQL queries

Security Features

  • Read-only access: Only SELECT, SHOW, DESCRIBE, and EXPLAIN statements are allowed; file-capable SELECT INTO and LOAD_FILE forms are rejected
  • Query validation: Prevents SQL injection and blocks any data modification attempts
  • Query timeout: Prevents long-running queries from consuming resources
  • Row limit: Prevents excessive data return
  • Exact large numbers: BIGINT and DECIMAL values are returned as strings to prevent precision loss

Installation

1. Install using one of these methods:

Install from NPM

# Install globally
npm install -g mysql-mcp-server

# Or install locally in your project
npm install mysql-mcp-server

Build from Source

# Clone the repository
git clone https://github.com/dpflucas/mysql-mcp-server.git
cd mysql-mcp-server

# Install dependencies and build
npm install
npm run build

2. Configure environment variables

The server requires the following environment variables:

  • MYSQL_HOST: Database server hostname
  • MYSQL_PORT: Database server port (default: 3306)
  • MYSQL_USER: Database username
  • MYSQL_PASSWORD: Database password (optional, but recommended for secure connections)
  • MYSQL_DATABASE: Default database name (optional)

3. Add to MCP settings

Add the following configuration to your MCP settings file:

If you installed via npm (Option 1):

{
"mcpServers": {
"mysq
Read from source at commit c084c716d5fdOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mysql-mcp-server --env MYSQL_PASSWORD=${MYSQL_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mysql-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MYSQL_PASSWORD": "${MYSQL_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
describe_tablereadShow the schema for a specific table
execute_querywriteExecute a read-only SQL query
list_databasesreadList all accessible databases on the MySQL server
list_tablesreadList all tables in a specified database
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
test-validators.js:22
"SELECT LOAD_FILE('/etc/passwd')",
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
test-validators.js:23
"SELECT load_file ( '/etc/passwd' )",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.worktreeinclude
.worktreeinclude
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, mysql2, @types/node, dotenv, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c084c716d5fdfull audit observations/trust-audit/mcp-server/dpflucas__mysql-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c084c716d5fdCAUTIONB89first audit
06

Questions

What is the MySQL MCP server?

An MCP server provides read-only access to MySQL databases.

What tools does MySQL expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MySQL safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does MySQL need?

It reads MYSQL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MySQL run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mysql-mcp-server at 0.1.4.

How current is this page?

The grade is for one exact copy of the source (c084c716d5fd), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement