Atlas / MCP servers / haymon-ai / Dbmcp

DbmcpBLOCK

mcp/haymon-ai/dbmcp-3

Database MCP server for MySQL, MariaDB, PostgreSQL, and SQLite - with builtin PII redaction and write-prevention

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/haymon-ai/dbmcp/actions/workflows/ci.yml) [](https://github.com/haymon-ai/dbmcp/releases/latest) [](LICENSE) [](https://dbmcp.haymon.ai/docs/)

A single-binary MCP server for SQL databases. Connect your AI assistant to MySQL/MariaDB, PostgreSQL, or SQLite with zero runtime dependencies.

[Website](https://dbmcp.haymon.ai) · [Documentation](https://dbmcp.haymon.ai/docs/) · [Releases](https://github.com/haymon-ai/dbmcp/releases)

Features ✨

  • Multi-database — MySQL/MariaDB, PostgreSQL, and SQLite from one binary
  • MCP tools — schema discovery (listDatabases, listTables, listViews, listTriggers, listFunctions, listProcedures, listMaterializedViews), data access (readQuery, writeQuery), DDL (createDatabase, dropDatabase, dropTable), and explainQuery. Read-only mode hides the write tools (writeQuery, createDatabase, dropDatabase, dropTable). See MCP Tools for per-backend availability.
  • Single binary — ~7 MB, no Python/Node/Docker needed
  • Multiple transports — stdio (for Claude Desktop, Cursor) and HTTP (for remote/multi-client)
  • Two-layer config — CLI flags > environment variables, with sensible defaults per backend

Install 📦

macOS, Linux, WSL:

curl -fsSL https://dbmcp.haymon.ai/install.sh | bash

Windows PowerShell:

irm https://dbmcp.haymon.ai/install.ps1 | iex

Windows CMD:

curl -fsSL https://dbmcp.haymon.ai/install.cmd -o install.cmd && install.cmd && del install.cmd

See the [installation docs

Read from source at commit 3153db29eef3OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (oci)
claude mcp add dbmcp:0.13.2 -- docker run -i --rm ghcr.io/haymon-ai/dbmcp:0.13.2:None stdio
claude-code (oci)
claude mcp add dbmcp:0.13.2 -- docker run -i --rm ghcr.io/haymon-ai/dbmcp:0.13.2:None http
03

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/pii/benches/corpus/api_key.toml:3
"GH_TOKEN=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/pii/benches/corpus/api_key.toml:10
"GH_TOKEN=ghp_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/pii/src/recognizers/generic/api_key.rs:82
"GH_TOKEN=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/pii/src/recognizers/generic/api_key.rs:83
&[("ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789", 0.6)],
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/pii/src/recognizers/generic/api_key.rs:99
("GH_TOKEN=ghp_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", &[]),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/pii/benches/corpus/private_key.toml:2
"-----BEGIN RSA PRIVATE KEY-----MIIEowIBAAKCAQEAfake==-----END RSA PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/pii/benches/corpus/private_key.toml:3
"-----BEGIN EC PRIVATE KEY-----MHcCAQEEIfake==-----END EC PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/pii/benches/corpus/private_key.toml:4
"-----BEGIN OPENSSH PRIVATE KEY-----base64data-----END OPENSSH PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/pii/benches/corpus/private_key.toml:9
"-----BEGIN RSA PRIVATE KEY-----base64-----END EC PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/pii/src/recognizers/generic/private_key.rs:29
const RSA: &str = "-----BEGIN RSA PRIVATE KEY-----\n\
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
crates/pii/benches/corpus/api_key.toml:4
"STRIPE=sk_live_aBcDeFgHiJkLmNoPqRsTuVwX",
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
crates/pii/src/recognizers/generic/api_key.rs:86
"STRIPE=sk_live_aBcDeFgHiJkLmNoPqRsTuVwX",
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
crates/pii/src/recognizers/generic/api_key.rs:87
&[("sk_live_aBcDeFgHiJkLmNoPqRsTuVwX", 0.6)],
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/config/src/http.rs:32
"http://127.0.0.1".into(),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/config/src/http.rs:34
"https://127.0.0.1".into(),
LOWInventory / provenance · inv.hidden_file · CWE-1104
.taplo.toml
.taplo.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/public/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:53
tar czf ../../../dbmcp-${{ matrix.target }}.tar.gz ${{ matrix.artifact }}
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/mysql/src/tools/create_database.rs:11
const DESCRIPTION: &str = include_str!("../../assets/tools/create_database/default.md");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/mysql/src/tools/drop_database.rs:11
const DESCRIPTION: &str = include_str!("../../assets/tools/drop_database/default.md");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/mysql/src/tools/drop_table.rs:12
const DESCRIPTION_PINNED: &str = include_str!("../../assets/tools/drop_table/pinned.md");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/mysql/src/tools/drop_table.rs:13
const DESCRIPTION_UNPINNED: &str = include_str!("../../assets/tools/drop_table/unpinned.md");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:83
"url": "http://127.0.0.1:9001/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/content/docs/configuration.mdx:83
| `--allowed-origins` | `http://localhost,http://127.0.0.1,https://localhost,https://127.0.0.1` | Allowed browser origins (comma-separated). Drives both CORS preflight and server-side `Origin` header
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/content/docs/configuration.mdx:220
"url": "http://127.0.0.1:9001/mcp"

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3153db29eef3full audit observations/trust-audit/mcp-server/haymon-ai__dbmcp-3.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083153db29eef3BLOCKF55first audit
05

Questions

What is the Dbmcp MCP server?

Database MCP server for MySQL, MariaDB, PostgreSQL, and SQLite - with builtin PII redaction and write-prevention

Is Dbmcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 13 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Dbmcp need?

No credential environment variables were found in its source, so it appears to need none.

How does Dbmcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as docs at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (3153db29eef3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement