Atlas / MCP servers / freepeak / DB

DBBLOCK

mcp/freepeak/db

A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
12 10r · 2w · 0d
Transport
streamable-http
License
MIT
Stars
431
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://goreportcard.com/report/github.com/FreePeak/db-mcp-server) [](https://pkg.go.dev/github.com/FreePeak/db-mcp-server) [](https://github.com/FreePeak/db-mcp-server/graphs/contributors)

A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.

Overview • Core Concepts • Features • Supported Databases • Deployment Options • Configuration • Available Tools • Examples • Troubleshooting • Contributing

Overview

The DB MCP Server provides a standardized way for AI models to interact with multiple databases simultaneously. Built on the FreePeak/cortex framework, it enables AI assistants to execute SQL queries, manage transactions, explore schemas, and analyze performance across different database systems through a unified interface.

Core Concepts

Multi-Database Support

Unlike traditional database connectors, DB MCP Server can connect to and interact with multiple databases concurrently:

{
"connections": [
{
"id": "mysql1",
"type": "mysql",
"host": "localhost",
"port": 3306,
"name": 
Read from source at commit d70ece80d3f1OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add db-mcp-server -- npx -y @freepeak/[email protected]
claude-desktop
{
  "mcpServers": {
    "db-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@freepeak/[email protected]"
      ]
    }
  }
}
03

Exposed tools (12)

10 read · 2 write · 0 destructive.

ToolRiskDescription
describereadShow columns, indexes, and row estimate for a table
executewriteExecute SQL statement
explainreadShow the database execution plan for a SQL statement
filter_tablesreadFind tables by substring match
healthreadReport connectivity, connection-pool state, and engine health statistics
listreadList files and directories in a given path
list_databasesreadList all available databases
performancereadAnalyze query performance
querywriteExecute SQL query
schemareadGet schema of
timescaledbreadPerform TimescaleDB operations
transactionreadManage transactions
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/domain/database.go:11
Exec(ctx context.Context, statement string, args ...interface{}) (Result, error)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/domain/database.go:39
Exec(ctx context.Context, statement string, args ...interface{}) (Result, error)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/repository/database_repository.go:59
Exec(ctx context.Context, query string, args ...interface{}) (sql.Result, error)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/repository/database_repository.go:96
func (a *DatabaseAdapter) Exec(ctx context.Context, statement string, args ...interface{}) (domain.Result, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/repository/database_repository.go:249
func (a *TxAdapter) Exec(ctx context.Context, statement string, args ...interface{}) (domain.Result, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/cycles/INDEX.md:17
| 01 | Read-only bypass fix + max_rows guardrail | ✅ Shipped (PR #85) | [cycle-01](cycle-01-read-only-bypass-and-maxrows.md) |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/cycles/cycle-01-read-only-bypass-and-maxrows.md:1
# Cycle 01 — Read-Only Bypass Fix + max_rows Guardrail
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
init-scripts/timescaledb/README.md:51
psql postgresql://timescale_user:timescale_password@localhost:15435/timescale_test
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
scripts/shell/timescaledb-test.sh:54
echo "  psql postgresql://timescale_user:timescale_password@localhost:15435/timescale_test"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
init-scripts/timescaledb/README.md:37
- **test_readonly**: Read-only access user (password: readonly_password)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
init-scripts/timescaledb/README.md:38
- **test_readwrite**: Read-write access user (password: readwrite_password)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
repomix-output.txt:7665
// Load .env file if it exists
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
repomix-output.txt:789
run: curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin v1.55.2

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha d70ece80d3f1full audit observations/trust-audit/mcp-server/freepeak__db.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01d70ece80d3f1BLOCKF55first audit
06

Questions

What is the DB MCP server?

A powerful multi-database server implementing the Model Context Protocol (MCP) to provide AI assistants with structured access to databases.

What tools does DB expose?

12 in total: 10 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is DB safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does DB need?

No credential environment variables were found in its source, so it appears to need none.

How does DB run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @freepeak/db-mcp-server at 1.12.0.

How current is this page?

The grade is for one exact copy of the source (d70ece80d3f1), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement