Atlas / MCP servers / guangxiangdebizi / MySQL

MySQLCAUTION

mcp/guangxiangdebizi/mysql-28

这是一个功能强大且易用的MySQL数据库MCP(Model Context Protocol)服务器,让你的AI助手可以安全地进行完整的数据库操作,支持多数据库连接管理、增删改查、事务管理和智能回滚功能。

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
17 13r · 3w · 1d
Transport
streamable-http
License
—
Stars
81
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

v4.0.0 - 全新架构重写,更简洁、更强大!

一个功能强大且易用的 MySQL 数据库 MCP(Model Context Protocol)服务器,支持 AI 助手安全地操作 MySQL 数据库。

🌟 核心特性

  • 🌐 StreamableHTTP 协议 - 基于最新 MCP 规范实现
  • 🔐 Header 预配置 - 凭证不暴露给 AI,安全可靠
  • 🤖 AI 动态管理 - AI 可以帮你添加/切换数据库连接
  • 🔗 多数据库支持 - 同时管理多个数据库,随时切换
  • 📊 完整 CRUD - 支持所有 SQL 操作
  • 🏗️ 模块化架构 - 清晰的目录结构,易于扩展

📦 安装

环境要求

  • Node.js 18+
  • MySQL 5.7+ 或 8.0+
  • MCP 客户端(Claude Desktop、Cursor 等)

安装步骤

# 克隆项目
git clone https://github.com/guangxiangdebizi/MySQL_MCP.git
cd MySQL_MCP

# 安装依赖
npm install

# 编译
npm run build

# 启动服务器
npm start

⚙️ 配置方法

方式一:Header 预配置(推荐)

编辑 MCP 配置文件:

Windows: %APPDATA%\Claude\claude_desktop_config.json macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Linux: ~/.config/Claude/claude_desktop_config.json

单数据库配置

{
"mcpServers": {
"mysql-mcp": {
"type": "streamableHttp",
"url": "http://localhost:3001/mcp",
"timeout": 600,
"headers": {
"X-MySQL-Host": "localhost",
"X-MySQL-Port": "3306",
"X-MySQL-User": "root",
"X-MySQL-Password": "your_password",
"X-MySQL-Database": "your_database"
}
}
}
}

多数据库配置

{
"mcpServers": {
"mysql-mcp": {
"type": "streamableHttp",
"url": "http://localhost:3001/mcp",
"timeout": 600,
"headers": {
"X-MySQL-Host-1": "prod.mysql.com",
"X-MySQL-User-1": "prod_user",
"X-MySQL-Password-1": "prod_pass",
"X-MySQL-Database-1": "production",

"X-MySQL-Host-2": "test.mysql.com",
"X-MySQL-User-2": "test_user",
"X-MySQL-Password-2": "test_pass",
"X-MySQL-Database-2": "testing"
}
}
}
}

优势:

  • ✅ 数据库凭证不暴露给 AI
  • ✅ 启动即连接,无需手动操作
  • ✅ 支持多数据库同时连接

方式二:AI 动态添加(灵活)

不配置 Header,让 AI 在对话中帮你添加连接:

{
"mcpServers": {
"mysql-mcp": {
"type": "streamableHttp",
"url": "http:
Read from source at commit bfa7c8065d32OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mysql-mcp-server -- npx -y @xingyuchen/[email protected]
claude-desktop
{
  "mcpServers": {
    "mysql-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@xingyuchen/[email protected]"
      ]
    }
  }
}
03

Exposed tools (17)

13 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_connectionwrite添加新的数据库连接
begin_transactionread开始数据库事务
commit_transactionwrite提交数据库事务
connect_databaseread连接到MySQL数据库
describe_tableread显示指定表的详细结构信息和样本数据
disconnect_databaseread断开数据库连接
execute_querywrite执行SQL查询语句(支持增删改查所有操作)
full_rollbackread完全回滚当前事务的所有操作
list_connectionsread列出所有数据库连接
remove_connectiondestructive移除指定的数据库连接
rollback_to_stepread回滚到指定的操作步骤
rollback_transactionread回滚数据库事务
select_databaseread选择活跃的数据库连接(后续SQL将在此数据库上执行)
show_databasesread显示所有可访问的数据库。自动使用当前活跃的数据库连接。
show_tablesread显示数据库中的所有表及其结构信息
show_transaction_historyread显示当前事务的操作历史
switch_active_connectionread切换当前活跃的数据库连接
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
dist/httpServer.js:875
console.log(`   - X-MySQL-Password: 数据库密码`);
MEDIUMPrompt injection · review.misleading_scope · CWE-94, CWE-1427
<listing:description>
Empowers AI assistants to perform comprehensive and secure operations on MySQL databases, including CRUD, transaction management, and intelligent rollback.
Why it matters. The listing description advertises transaction management and rollback capabilities, but the current v4.0.x release removed all transaction tools (begin_transaction, commit_transaction, rollback_transaction, full_rollback, rollback_to_step, show_transaction_history) per the CHANGELOG, making the des
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_connection
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, mysql2, winston, winston-daily-rotate-file, express, cors, dotenv, @types/node
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha bfa7c8065d32full audit observations/trust-audit/mcp-server/guangxiangdebizi__mysql-28.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07bfa7c8065d32CAUTIONB84first audit
06

Questions

What is the MySQL MCP server?

这是一个功能强大且易用的MySQL数据库MCP(Model Context Protocol)服务器,让你的AI助手可以安全地进行完整的数据库操作,支持多数据库连接管理、增删改查、事务管理和智能回滚功能。

What tools does MySQL expose?

17 in total: 13 read-only, 3 that write, and 1 that can delete or overwrite (remove_connection). Every one is listed on this page with its risk.

Is MySQL safe to connect to an agent?

With care. The audit graded it B (84/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MySQL need?

No credential environment variables were found in its source, so it appears to need none.

How does MySQL run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @xingyuchen/mysql-mcp-server at 4.0.7.

How current is this page?

The grade is for one exact copy of the source (bfa7c8065d32), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement