PostgreSQLCAUTION
A Powerful PostgreSQL MCP server with 14 consolidated database management tools for AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@HenkDz/postgresql-mcp-server)
A Model Context Protocol (MCP) server that provides comprehensive PostgreSQL database management capabilities for AI assistants.
🚀 What's New: This server has been completely redesigned from 46 individual tools to 18 intelligent tools through consolidation (34→8 meta-tools) and enhancement (+4 new tools), providing better AI discovery while adding powerful data manipulation and comment management capabilities.
Breaking Changes in 2.0.0
Version 2.0.0 introduces security boundaries that intentionally change default behavior from the 1.x line:
- The server starts in
readonlymode. Mutations, DDL, role administration, filesystem import/export, and arbitrary SQL require--security-mode write,--security-mode admin, or--security-mode unsafeas appropriate. - Destructive operations such as drops, resets, broad role grants, and arbitrary SQL require
--allow-destructive. - Per-tool
connectionString,sourceConnectionString, andtargetConnectionStringarguments are disabled by default. Use server-level--connection-stringorPOSTGRES_CONNECTION_STRING, or explicitly opt in with--allow-tool-connection-string. - Legacy string
whereclauses are rejected for mutation, index, export, and copy filters. Use structuredwherepredicates, orrawWhereonly with--security-mode unsafe --allow-destructive. - Multi-statement
pg_execute_sqlcalls must usetransactional: true,expectRows: false, and no bindparameters. - Tool schemas reject unknown fields, so misspelled or unintended inputs fail before connection resolution.
- User and target identifiers are restricted to
820487637aa9OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add postgres-mcp-server -- npx -y @henkey/[email protected]
{
"mcpServers": {
"postgres-mcp-server": {
"command": "npx",
"args": [
"-y",
"@henkey/[email protected]"
]
}
}
}Exposed tools (57)
22 read · 18 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
pg_alter_table | destructive | Alter an existing table (add/modify/drop columns) |
pg_alter_user | read | Alter an existing PostgreSQL user/role |
pg_analyze_database | read | Analyze PostgreSQL database configuration and performance |
pg_analyze_index_usage | read | Find unused, duplicate, and low-usage indexes to optimize database performance |
pg_copy_between_databases | read | Copy data between two databases |
pg_create_constraint | write | Create a constraint (unique, check, or primary key) |
pg_create_enum | write | Create a new ENUM type in the database |
pg_create_foreign_key | write | Create a foreign key constraint |
pg_create_function | write | Create or replace a PostgreSQL function |
pg_create_index | write | Create a new index on a table |
pg_create_rls_policy | write | Create a Row-Level Security policy |
pg_create_table | write | Create a new table in the database |
pg_create_trigger | write | Create a PostgreSQL trigger |
pg_create_user | write | Create a new PostgreSQL user/role |
pg_debug_database | read | Debug common PostgreSQL issues |
pg_disable_rls | write | Disable Row-Level Security on a table |
pg_drop_constraint | destructive | Drop a constraint |
pg_drop_foreign_key | destructive | Drop a foreign key constraint |
pg_drop_function | destructive | Drop a PostgreSQL function |
pg_drop_index | destructive | Drop an existing index |
pg_drop_rls_policy | destructive | Drop a Row-Level Security policy |
pg_drop_trigger | destructive | Drop a PostgreSQL trigger |
pg_drop_user | destructive | Drop a PostgreSQL user/role |
pg_edit_rls_policy | write | Edit an existing Row-Level Security policy |
pg_enable_rls | write | Enable Row-Level Security on a table |
pg_execute_mutation | destructive | Execute data modification operations (INSERT/UPDATE/DELETE/UPSERT) - operation= |
pg_execute_query | write | Execute SELECT queries and data retrieval operations - operation= |
pg_execute_sql | write | Execute arbitrary SQL statements - sql= |
pg_explain_query | read | EXPLAIN/EXPLAIN ANALYZE for queries to understand execution plans |
pg_export_table_data | read | Export table data to JSON or CSV format |
pg_get_constraints | read | List all constraints (primary keys, foreign keys, unique, check) |
pg_get_enums | read | Get information about PostgreSQL ENUM types |
pg_get_functions | read | Get information about PostgreSQL functions |
pg_get_indexes | read | List indexes with size and usage statistics |
pg_get_query_stats | read | Query statistics from pg_stat_statements with cache hit ratios |
pg_get_rls_policies | read | Get Row-Level Security policies |
pg_get_schema_info | read | Get schema information for a database or specific table |
pg_get_slow_queries | read | Find slow running queries using pg_stat_statements |
pg_get_triggers | read | Get information about PostgreSQL triggers |
pg_get_user_permissions | read | Get permissions for a user/role or all users |
pg_grant_permissions | read | Grant permissions to a user/role |
pg_import_table_data | write | Import data from JSON or CSV file into a table |
pg_list_users | read | List all users/roles in the database |
pg_manage_comments | destructive | Manage PostgreSQL object comments - get, set, remove comments on tables, columns, functions, and other database objects. Examples: operation= |
pg_manage_constraints | destructive | Manage PostgreSQL constraints - get, create foreign keys, drop foreign keys, create constraints, drop constraints. Examples: operation= |
pg_manage_functions | destructive | Manage PostgreSQL functions - get, create, or drop functions with a single tool. Examples: operation= |
pg_manage_indexes | destructive | Manage PostgreSQL indexes - get, create, drop, reindex, and analyze usage with a single tool. Examples: operation= |
pg_manage_query | read | Manage PostgreSQL query analysis and performance - operation= |
pg_manage_rls | write | Manage PostgreSQL Row-Level Security - enable/disable RLS and manage policies. Examples: operation= |
pg_manage_schema | write | Manage PostgreSQL schema - get schema info, create/alter tables, manage enums. Examples: operation= |
pg_manage_triggers | destructive | Manage PostgreSQL triggers - get, create, drop, and enable/disable triggers. Examples: operation= |
pg_manage_users | destructive | Manage PostgreSQL users and permissions - create, drop, alter users, grant/revoke permissions. Examples: operation= |
pg_monitor_database | read | Get real-time monitoring information for a PostgreSQL database |
pg_reindex | read | Rebuild indexes to improve performance and reclaim space |
pg_reset_query_stats | destructive | Reset pg_stat_statements statistics (all or specific query) |
pg_revoke_permissions | destructive | Revoke permissions from a user/role |
pg_set_trigger_state | write | Enable or disable a PostgreSQL trigger |
Trust audit
CAUTIONgrade D · trust 67/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (12)
POSTGRES_MCP_INTEGRATION_CONNECTION_STRING: postgresql://postgres:postgres@localhost:5432/postgres
POSTGRES_MCP_INTEGRATION_CONNECTION_STRING: postgresql://postgres:postgres@localhost:5432/postgres
npx @henkey/postgres-mcp-server --connection-string "postgresql://readonly_user:pass@host:5432/db"
npx @henkey/postgres-mcp-server --security-mode write --connection-string "postgresql://app_writer:pass@host:5432/db"
npx @henkey/postgres-mcp-server --security-mode admin --allow-destructive --connection-string "postgresql://admin_user:pass@host:5432/db"
PASSWORD :'mcp_readonly_password'
PASSWORD :'mcp_schema_admin_password'
where: "token = 'raw-migration-secret'"
new Error("password=db-secret failed while exporting WHERE token = 'raw-migration-secret'")rawWhere: "token = 'raw-migration-secret'"
pg_alter_table, pg_drop_constraint, pg_drop_foreign_key, pg_drop_function, pg_drop_index, pg_drop_rls_policy, pg_drop_trigger, pg_drop_user, pg_execute_mutation, pg_manage_comments, pg_manage_constrai
@modelcontextprotocol/sdk, commander, pg, pg-monitor, pg-query-stream, zod, zod-to-json-schema, @types/node
Gates applied: no_behavioural_pass.
820487637aa9full audit observations/trust-audit/mcp-server/henkdz__postgresql-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 820487637aa9 | CAUTION | D | 67 | first audit |
Questions
What is the PostgreSQL MCP server?
A Powerful PostgreSQL MCP server with 14 consolidated database management tools for AI assistants.
What tools does PostgreSQL expose?
57 in total: 22 read-only, 18 that write, and 17 that can delete or overwrite (pg_alter_table, pg_drop_constraint, pg_drop_foreign_key, pg_drop_function, pg_drop_index). Every one is listed on this page with its risk.
Is PostgreSQL safe to connect to an agent?
With care. The audit graded it D (67/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PostgreSQL need?
No credential environment variables were found in its source, so it appears to need none.
How does PostgreSQL run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @henkey/postgres-mcp-server at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (820487637aa9), read on 2026-10-06. The repository is watched and re-audited when it changes.