Atlas / MCP servers / erikej / SqlServer.Rules

SqlServer.RulesBLOCK

mcp/erikej/sqlserver-rules

140+ T-SQL static code analysis rules for SQL Database Projects and ad-hoc scripts

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
241
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[marketplace]: https://marketplace.visualstudio.com/items?itemName=ErikEJ.TSqlAnalyzer [ssmsmarketplace]: https://ssmsgallery.azurewebsites.net/extension/TSqlAnalyzerSsms.f1322c34-dfaa-4842-8933-b439626da91d [vsixgallery]: http://www.vsixgallery.com/extension/SqlAnalyzer.abc6ba2-edd5-4419-8646-a55d0a83f7ff/

[](https://mcptoplist.com/server/glama%2FErikEJ%2FSqlServer.Rules)

[](https://www.nuget.org/packages/ErikEJ.DacFX.SqlServer.Rules)

Overview

A library of SQL best practices implemented as over 140 database code analysis rules checked at build time.

The rules can be added as NuGet packages to SQL Database projects:

For a complete list of the current rules we have implemented see here.

Component Stack

flowchart TD
VS["Visual Studio T-SQL AnalyzerLive feedback in Visual Studio"]
SSMS["SSMS T-SQL AnalyzerLive feedback in SQL Server Management Studio"]
VSC["VS Code T-SQL AnalyzerLive feedback in Visual Studio Code"]
CLI["T-SQL Analyzer CLItsqlanalyze command line tool"]
MBSQL["SQL Database ProjectsBuild-time SQL Project analysis"]
RULES["SqlServer.Rules(NuGet package)Static SQL code analysis rules"]
MCP["MCP ServerAI Agent integration for SQL code analysis rul
Read from source at commit afd5da792c46OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add tsqlanalyzerextension -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "tsqlanalyzerextension": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/ignoring_rules.md:8
- GLOBAL IGNORE {RuleId}: Ignores all occurrences of that rule within the file.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/ignoring_rules.md:35
Now you could just add ignores for each occasion of this rule violation, but instead you could use a global ignore to ignore all violations of that rule within the stored procedure.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Design/SRD0001.md:1
# SQL Server Rule: SRD0001
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Design/SRD0002.md:1
# SQL Server Rule: SRD0002
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Design/SRD0003.md:1
# SQL Server Rule: SRD0003
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Design/SRD0004.md:1
# SQL Server Rule: SRD0004
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Design/SRD0005.md:1
# SQL Server Rule: SRD0005
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/SqlServer.Rules/key.snk
key.snk
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/SqlAnalyzerCli/testfiles/Chinook.dacpac
Chinook.dacpac
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode-extension/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
vscode-extension/package.json
@types/node, @vscode/vsce, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
tools/SqlAnalyzerCli/.mcp/server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha afd5da792c46full audit observations/trust-audit/mcp-server/erikej__sqlserver-rules.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06afd5da792c46BLOCKD69first audit
05

Questions

What is the SqlServer.Rules MCP server?

140+ T-SQL static code analysis rules for SQL Database Projects and ad-hoc scripts

Is SqlServer.Rules safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does SqlServer.Rules need?

No credential environment variables were found in its source, so it appears to need none.

How does SqlServer.Rules run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as tsqlanalyzerextension at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (afd5da792c46), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement