Atlas / MCP servers / henkdz / PostgreSQL

PostgreSQLCAUTION

mcp/henkdz/postgresql-1

A Powerful PostgreSQL MCP server with 14 consolidated database management tools for AI assistants.

Verdict
CAUTION
Grade
D
Trust score
67 /100
Exposed tools
57 22r · 18w · 17d
Transport
stdio
License
AGPL-3.0
Stars
200
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@HenkDz/postgresql-mcp-server)

A Model Context Protocol (MCP) server that provides comprehensive PostgreSQL database management capabilities for AI assistants.

🚀 What's New: This server has been completely redesigned from 46 individual tools to 18 intelligent tools through consolidation (34→8 meta-tools) and enhancement (+4 new tools), providing better AI discovery while adding powerful data manipulation and comment management capabilities.

Breaking Changes in 2.0.0

Version 2.0.0 introduces security boundaries that intentionally change default behavior from the 1.x line:

  • The server starts in readonly mode. Mutations, DDL, role administration, filesystem import/export, and arbitrary SQL require --security-mode write, --security-mode admin, or --security-mode unsafe as appropriate.
  • Destructive operations such as drops, resets, broad role grants, and arbitrary SQL require --allow-destructive.
  • Per-tool connectionString, sourceConnectionString, and targetConnectionString arguments are disabled by default. Use server-level --connection-string or POSTGRES_CONNECTION_STRING, or explicitly opt in with --allow-tool-connection-string.
  • Legacy string where clauses are rejected for mutation, index, export, and copy filters. Use structured where predicates, or rawWhere only with --security-mode unsafe --allow-destructive.
  • Multi-statement pg_execute_sql calls must use transactional: true, expectRows: false, and no bind parameters.
  • Tool schemas reject unknown fields, so misspelled or unintended inputs fail before connection resolution.
  • User and target identifiers are restricted to
Read from source at commit 820487637aa9OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add postgres-mcp-server -- npx -y @henkey/[email protected]
claude-desktop
{
  "mcpServers": {
    "postgres-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@henkey/[email protected]"
      ]
    }
  }
}
03

Exposed tools (57)

22 read · 18 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
pg_alter_tabledestructiveAlter an existing table (add/modify/drop columns)
pg_alter_userreadAlter an existing PostgreSQL user/role
pg_analyze_databasereadAnalyze PostgreSQL database configuration and performance
pg_analyze_index_usagereadFind unused, duplicate, and low-usage indexes to optimize database performance
pg_copy_between_databasesreadCopy data between two databases
pg_create_constraintwriteCreate a constraint (unique, check, or primary key)
pg_create_enumwriteCreate a new ENUM type in the database
pg_create_foreign_keywriteCreate a foreign key constraint
pg_create_functionwriteCreate or replace a PostgreSQL function
pg_create_indexwriteCreate a new index on a table
pg_create_rls_policywriteCreate a Row-Level Security policy
pg_create_tablewriteCreate a new table in the database
pg_create_triggerwriteCreate a PostgreSQL trigger
pg_create_userwriteCreate a new PostgreSQL user/role
pg_debug_databasereadDebug common PostgreSQL issues
pg_disable_rlswriteDisable Row-Level Security on a table
pg_drop_constraintdestructiveDrop a constraint
pg_drop_foreign_keydestructiveDrop a foreign key constraint
pg_drop_functiondestructiveDrop a PostgreSQL function
pg_drop_indexdestructiveDrop an existing index
pg_drop_rls_policydestructiveDrop a Row-Level Security policy
pg_drop_triggerdestructiveDrop a PostgreSQL trigger
pg_drop_userdestructiveDrop a PostgreSQL user/role
pg_edit_rls_policywriteEdit an existing Row-Level Security policy
pg_enable_rlswriteEnable Row-Level Security on a table
pg_execute_mutationdestructiveExecute data modification operations (INSERT/UPDATE/DELETE/UPSERT) - operation=
pg_execute_querywriteExecute SELECT queries and data retrieval operations - operation=
pg_execute_sqlwriteExecute arbitrary SQL statements - sql=
pg_explain_queryreadEXPLAIN/EXPLAIN ANALYZE for queries to understand execution plans
pg_export_table_datareadExport table data to JSON or CSV format
pg_get_constraintsreadList all constraints (primary keys, foreign keys, unique, check)
pg_get_enumsreadGet information about PostgreSQL ENUM types
pg_get_functionsreadGet information about PostgreSQL functions
pg_get_indexesreadList indexes with size and usage statistics
pg_get_query_statsreadQuery statistics from pg_stat_statements with cache hit ratios
pg_get_rls_policiesreadGet Row-Level Security policies
pg_get_schema_inforeadGet schema information for a database or specific table
pg_get_slow_queriesreadFind slow running queries using pg_stat_statements
pg_get_triggersreadGet information about PostgreSQL triggers
pg_get_user_permissionsreadGet permissions for a user/role or all users
pg_grant_permissionsreadGrant permissions to a user/role
pg_import_table_datawriteImport data from JSON or CSV file into a table
pg_list_usersreadList all users/roles in the database
pg_manage_commentsdestructiveManage PostgreSQL object comments - get, set, remove comments on tables, columns, functions, and other database objects. Examples: operation=
pg_manage_constraintsdestructiveManage PostgreSQL constraints - get, create foreign keys, drop foreign keys, create constraints, drop constraints. Examples: operation=
pg_manage_functionsdestructiveManage PostgreSQL functions - get, create, or drop functions with a single tool. Examples: operation=
pg_manage_indexesdestructiveManage PostgreSQL indexes - get, create, drop, reindex, and analyze usage with a single tool. Examples: operation=
pg_manage_queryreadManage PostgreSQL query analysis and performance - operation=
pg_manage_rlswriteManage PostgreSQL Row-Level Security - enable/disable RLS and manage policies. Examples: operation=
pg_manage_schemawriteManage PostgreSQL schema - get schema info, create/alter tables, manage enums. Examples: operation=
pg_manage_triggersdestructiveManage PostgreSQL triggers - get, create, drop, and enable/disable triggers. Examples: operation=
pg_manage_usersdestructiveManage PostgreSQL users and permissions - create, drop, alter users, grant/revoke permissions. Examples: operation=
pg_monitor_databasereadGet real-time monitoring information for a PostgreSQL database
pg_reindexreadRebuild indexes to improve performance and reclaim space
pg_reset_query_statsdestructiveReset pg_stat_statements statistics (all or specific query)
pg_revoke_permissionsdestructiveRevoke permissions from a user/role
pg_set_trigger_statewriteEnable or disable a PostgreSQL trigger
04

Trust audit

CAUTIONgrade D · trust 67/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (12)

MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:74
POSTGRES_MCP_INTEGRATION_CONNECTION_STRING: postgresql://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/publish.yml:49
POSTGRES_MCP_INTEGRATION_CONNECTION_STRING: postgresql://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:142
npx @henkey/postgres-mcp-server --connection-string "postgresql://readonly_user:pass@host:5432/db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:145
npx @henkey/postgres-mcp-server --security-mode write --connection-string "postgresql://app_writer:pass@host:5432/db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:148
npx @henkey/postgres-mcp-server --security-mode admin --allow-destructive --connection-string "postgresql://admin_user:pass@host:5432/db"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/POSTGRES_ROLES.md:37
PASSWORD :'mcp_readonly_password'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/POSTGRES_ROLES.md:94
PASSWORD :'mcp_schema_admin_password'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tools/migration.test.ts:189
where: "token = 'raw-migration-secret'"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tools/migration.test.ts:225
new Error("password=db-secret failed while exporting WHERE token = 'raw-migration-secret'")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tools/migration.test.ts:235
rawWhere: "token = 'raw-migration-secret'"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
pg_alter_table, pg_drop_constraint, pg_drop_foreign_key, pg_drop_function, pg_drop_index, pg_drop_rls_policy, pg_drop_trigger, pg_drop_user, pg_execute_mutation, pg_manage_comments, pg_manage_constrai
Why it matters. 17 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, pg, pg-monitor, pg-query-stream, zod, zod-to-json-schema, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 820487637aa9full audit observations/trust-audit/mcp-server/henkdz__postgresql-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06820487637aa9CAUTIOND67first audit
06

Questions

What is the PostgreSQL MCP server?

A Powerful PostgreSQL MCP server with 14 consolidated database management tools for AI assistants.

What tools does PostgreSQL expose?

57 in total: 22 read-only, 18 that write, and 17 that can delete or overwrite (pg_alter_table, pg_drop_constraint, pg_drop_foreign_key, pg_drop_function, pg_drop_index). Every one is listed on this page with its risk.

Is PostgreSQL safe to connect to an agent?

With care. The audit graded it D (67/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PostgreSQL need?

No credential environment variables were found in its source, so it appears to need none.

How does PostgreSQL run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @henkey/postgres-mcp-server at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (820487637aa9), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement