DBBLOCK
A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://goreportcard.com/report/github.com/FreePeak/db-mcp-server) [](https://pkg.go.dev/github.com/FreePeak/db-mcp-server) [](https://github.com/FreePeak/db-mcp-server/graphs/contributors)
A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.
Overview • Core Concepts • Features • Supported Databases • Deployment Options • Configuration • Available Tools • Examples • Troubleshooting • Contributing
Overview
The DB MCP Server provides a standardized way for AI models to interact with multiple databases simultaneously. Built on the FreePeak/cortex framework, it enables AI assistants to execute SQL queries, manage transactions, explore schemas, and analyze performance across different database systems through a unified interface.
Core Concepts
Multi-Database Support
Unlike traditional database connectors, DB MCP Server can connect to and interact with multiple databases concurrently:
{
"connections": [
{
"id": "mysql1",
"type": "mysql",
"host": "localhost",
"port": 3306,
"name": d70ece80d3f1OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add db-mcp-server -- npx -y @freepeak/[email protected]
{
"mcpServers": {
"db-mcp-server": {
"command": "npx",
"args": [
"-y",
"@freepeak/[email protected]"
]
}
}
}Exposed tools (12)
10 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe | read | Show columns, indexes, and row estimate for a table |
execute | write | Execute SQL statement |
explain | read | Show the database execution plan for a SQL statement |
filter_tables | read | Find tables by substring match |
health | read | Report connectivity, connection-pool state, and engine health statistics |
list | read | List files and directories in a given path |
list_databases | read | List all available databases |
performance | read | Analyze query performance |
query | write | Execute SQL query |
schema | read | Get schema of |
timescaledb | read | Perform TimescaleDB operations |
transaction | read | Manage transactions |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (15)
Exec(ctx context.Context, statement string, args ...interface{}) (Result, error)Exec(ctx context.Context, statement string, args ...interface{}) (Result, error)Exec(ctx context.Context, query string, args ...interface{}) (sql.Result, error)func (a *DatabaseAdapter) Exec(ctx context.Context, statement string, args ...interface{}) (domain.Result, error) {func (a *TxAdapter) Exec(ctx context.Context, statement string, args ...interface{}) (domain.Result, error) {| 01 | Read-only bypass fix + max_rows guardrail | ✅ Shipped (PR #85) | [cycle-01](cycle-01-read-only-bypass-and-maxrows.md) |
# Cycle 01 — Read-Only Bypass Fix + max_rows Guardrail
psql postgresql://timescale_user:timescale_password@localhost:15435/timescale_test
echo " psql postgresql://timescale_user:timescale_password@localhost:15435/timescale_test"
streamable-http
.golangci.yml
- **test_readonly**: Read-only access user (password: readonly_password)
- **test_readwrite**: Read-write access user (password: readwrite_password)
// Load .env file if it exists
run: curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin v1.55.2
Gates applied: instruction_override, no_behavioural_pass.
d70ece80d3f1full audit observations/trust-audit/mcp-server/freepeak__db.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | d70ece80d3f1 | BLOCK | F | 55 | first audit |
Questions
What is the DB MCP server?
A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.
What tools does DB expose?
12 in total: 10 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is DB safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does DB need?
No credential environment variables were found in its source, so it appears to need none.
How does DB run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @freepeak/db-mcp-server at 1.12.0.
How current is this page?
The grade is for one exact copy of the source (d70ece80d3f1), read on 2026-10-01. The repository is watched and re-audited when it changes.