SqlServer.RulesBLOCK
140+ T-SQL static code analysis rules for SQL Database Projects and ad-hoc scripts
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[marketplace]: https://marketplace.visualstudio.com/items?itemName=ErikEJ.TSqlAnalyzer [ssmsmarketplace]: https://ssmsgallery.azurewebsites.net/extension/TSqlAnalyzerSsms.f1322c34-dfaa-4842-8933-b439626da91d [vsixgallery]: http://www.vsixgallery.com/extension/SqlAnalyzer.abc6ba2-edd5-4419-8646-a55d0a83f7ff/
[](https://mcptoplist.com/server/glama%2FErikEJ%2FSqlServer.Rules)
[](https://www.nuget.org/packages/ErikEJ.DacFX.SqlServer.Rules)
Overview
A library of SQL best practices implemented as over 140 database code analysis rules checked at build time.
The rules can be added as NuGet packages to SQL Database projects:
- Modern SDK-style projects: MSBuild.Sdk.SqlProj and Microsoft.Build.Sql
- Classic .sqlproj: Legacy SSDT projects (Visual Studio 2017+ required)
For a complete list of the current rules we have implemented see here.
Component Stack
flowchart TD VS["Visual Studio T-SQL AnalyzerLive feedback in Visual Studio"] SSMS["SSMS T-SQL AnalyzerLive feedback in SQL Server Management Studio"] VSC["VS Code T-SQL AnalyzerLive feedback in Visual Studio Code"] CLI["T-SQL Analyzer CLItsqlanalyze command line tool"] MBSQL["SQL Database ProjectsBuild-time SQL Project analysis"] RULES["SqlServer.Rules(NuGet package)Static SQL code analysis rules"] MCP["MCP ServerAI Agent integration for SQL code analysis rul
afd5da792c46OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add tsqlanalyzerextension -- npx -y [email protected]
{
"mcpServers": {
"tsqlanalyzerextension": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
- GLOBAL IGNORE {RuleId}: Ignores all occurrences of that rule within the file.Now you could just add ignores for each occasion of this rule violation, but instead you could use a global ignore to ignore all violations of that rule within the stored procedure.
# SQL Server Rule: SRD0001
# SQL Server Rule: SRD0002
# SQL Server Rule: SRD0003
# SQL Server Rule: SRD0004
# SQL Server Rule: SRD0005
key.snk
Chinook.dacpac
.vscodeignore
@types/node, @vscode/vsce, typescript
Gates applied: instruction_override, no_behavioural_pass.
afd5da792c46full audit observations/trust-audit/mcp-server/erikej__sqlserver-rules.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | afd5da792c46 | BLOCK | D | 69 | first audit |
Questions
What is the SqlServer.Rules MCP server?
140+ T-SQL static code analysis rules for SQL Database Projects and ad-hoc scripts
Is SqlServer.Rules safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does SqlServer.Rules need?
No credential environment variables were found in its source, so it appears to need none.
How does SqlServer.Rules run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as tsqlanalyzerextension at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (afd5da792c46), read on 2026-10-06. The repository is watched and re-audited when it changes.