Atlas / MCP servers / hannesrudolph / SQLite Explorer

SQLite ExplorerCAUTION

mcp/hannesrudolph/sqlite-explorer

An MCP server that provides safe, read-only access to SQLite databases through Model Context Protocol (MCP). This server is built with the FastMCP framework, which enables LLMs to explore and query SQLite databases with built-in safety features and query validation.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
3 2r · 1w · 0d
Transport
—
License
—
Stars
108
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/hannesrudolph-sqlite-explorer-fastmcp-mcp-server)

An MCP server that provides safe, read-only access to SQLite databases through Model Context Protocol (MCP). This server is built with the FastMCP framework, which enables LLMs to explore and query SQLite databases with built-in safety features and query validation.

📋 System Requirements

  • Python 3.6+
  • SQLite database file (path specified via environment variable)

📦 Dependencies

Install all required dependencies:

# Using pip
pip install -r requirements.txt

Required Packages

  • fastmcp: Framework for building Model Context Protocol servers

All dependencies are specified in requirements.txt for easy installation.

📑 Table of Contents

  • System Requirements
  • Dependencies
  • MCP Tools
  • Getting Started
  • Installation Options
  • Claude Desktop
  • Cline VSCode Plugin
  • Safety Features
  • Development Documentation
  • Environment Variables

🛠️ MCP Tools

The server exposes the following tools to LLMs:

read_query

Execute a SELECT query on the database with built-in safety validations. Features:

  • Query validation and sanitization
  • Parameter binding support
  • Row limit enforcement
  • Results formatted as dictionaries

list_tables

List all available tables in the database with their names.

describe_table

Get detailed schema information for a specific table, including:

  • Column names and types
  • NULL constraints
  • Default values
  • Primary key information

🚀 Getting Started

Clone the repository:

git clone https:
Read from source at commit d460e65add58OBSERVED · 2026-10-07
02

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
describe_tablereadGet detailed information about a table
list_tablesreadList all tables in the Messages database.
read_querywriteExecute a query on the Messages database.
03

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (9)

MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
fastmcp-documentation.txt:734
DB_DSN = "postgresql://postgres:postgres@localhost:54320/memory_db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
fastmcp-documentation.txt:994
"postgresql://postgres:postgres@localhost:54320/postgres"
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
fastmcp-documentation.txt:471
# Or load from a .env file
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
fastmcp-documentation.txt:3158
help="Load environment variables from a .env file",
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
fastmcp-documentation.txt:3211
# Load from .env file if specified
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
fastmcp-documentation.txt:3220
logger.error(f"Failed to load .env file: {e}")
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-documentation.txt:2830
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
mcp-documentation.txt:4111
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha d460e65add58full audit observations/trust-audit/mcp-server/hannesrudolph__sqlite-explorer.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d460e65add58CAUTIONB86first audit
05

Questions

What is the SQLite Explorer MCP server?

An MCP server that provides safe, read-only access to SQLite databases through Model Context Protocol (MCP). This server is built with the FastMCP framework, which enables LLMs to explore and query SQLite databases with built-in safety features and query validation.

What tools does SQLite Explorer expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SQLite Explorer safe to connect to an agent?

With care. The audit graded it B (86/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SQLite Explorer need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (d460e65add58), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement