Atlas / MCP servers / julien040 / Anyquery

AnyqueryCAUTION

mcp/julien040/anyquery

One SQL interface for 60+ tools (e.g., GitHub, Notion, Airtable). Plug into any LLM through MCP.

Verdict
CAUTION
Grade
C
Trust score
72 /100
Exposed tools
12 11r · 1w · 0d
Transport
—
License
NOASSERTION
Stars
1,775
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://anyquery.dev) [](https://github.com/julien040/anyquery/issues) [](https://anyquery.dev/integrations/) [](https://anyquery.dev/queries) [](https://pkg.go.dev/github.com/julien040/anyquery/namespace) [](https://archestra.ai/mcp-catalog/julien040__anyquery)

Sponsored by

Fluxion AI - Reliable, cost-efficient access to GPT, Claude, and other leading AI models<

Read from source at commit f8a21f9eee34OBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add anyquery-website --env ANYQUERY_PASSWORD=${ANYQUERY_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "anyquery-website": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANYQUERY_PASSWORD": "${ANYQUERY_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (12)

11 read · 1 write · 0 destructive.

ToolRiskDescription
cryptoreadHashing, encoding and decoding data
definereadUser-defined functions and dynamic sql
fileiowriteRead and write files
fuzzyreadFuzzy string matching and phonetics
ipaddrreadIP address manipulation
mathreadMath functions
regexpreadRegular expressions
statsreadMath statistics
textreadString functions and Unicode
timereadHigh-precision date/time
uuidreadUniversally Unique IDentifiers
vsvreadCSV files as virtual tables
04

Trust audit

CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (12 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
plugins/sharedObject/nalgeon/sqlean/bun.lockb
bun.lockb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
other/websocket_tunnel/server/Caddyfile:17
to http://127.0.0.1:5566
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
other/websocket_tunnel/server/Caddyfile:49
to http://127.0.0.1:5566
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
other/sqlparser/reserved_vars.go:121
const staticBvar100 = "vtg10vtg11vtg12vtg13vtg14vtg15vtg16vtg17vtg18vtg19vtg20vtg21vtg22vtg23vtg24vtg25vtg26vtg27vtg28vtg29vtg30vtg31vtg32vtg33vtg34vtg35vtg36vtg37vtg38vtg39vtg40vtg41vtg42vtg43vtg44vt
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
controller/dev.go:496
fmt.Println("🧑💻 To develop, launch `anyquery --dev` in developer mode with the flag --dev")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ignore
.ignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/airtable/.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/asana/.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/atlascloud/.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
module/source_test.go:47
"/etc/passwd?/../../../../../../../allowed/decoy",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
module/source_test.go:48
"/etc/passwd#/../../../../../../../allowed/decoy",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
module/source_test.go:152
mustError(t, "file:///etc/passwd?/../../allowed/x")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
module/source_test.go:435
"/allowed/../../../etc/passwd?/../../../../../../../allowed/decoy",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
module/source_test.go:436
"/allowed/../../../etc/passwd#/../../../../../../../allowed/decoy",
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
module/restrictions_test.go:25
if err := checkSrc(r, "http://169.254.169.254/"); err != nil {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
module/restrictions_test.go:38
if err := checkSrc(denied, "http://169.254.169.254/latest/meta-data/"); err == nil {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
namespace/sandbox_test.go:82
_, err := conn.ExecContext(ctx, "CREATE VIRTUAL TABLE meta USING csv_reader('http://169.254.169.254/latest/meta-data/')")
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
website/src/content/docs/docs/usage/sandbox.md:67
`--allow-remote` is all-or-nothing: there is no IP or SSRF filtering underneath it (no loopback/RFC1918 blocking), only a scheme check. When enabled, the server can again reach internal addresses and 
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
module/restrictions_test.go:25
if err := checkSrc(r, "http://169.254.169.254/"); err != nil {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
module/restrictions_test.go:38
if err := checkSrc(denied, "http://169.254.169.254/latest/meta-data/"); err == nil {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
namespace/sandbox_test.go:82
_, err := conn.ExecContext(ctx, "CREATE VIRTUAL TABLE meta USING csv_reader('http://169.254.169.254/latest/meta-data/')")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
_examples/drizzle/package.json
drizzle-kit, drizzle-orm, mysql2
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
plugins/sharedObject/nalgeon/sqlean/package.json
@iarna/toml, @types/bun
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
@astrojs/alpinejs, @astrojs/check, @astrojs/sitemap, @astrojs/starlight, @astrojs/starlight-tailwind, @tailwindcss/vite, @types/alpinejs, alpinejs
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha f8a21f9eee34full audit observations/trust-audit/mcp-server/julien040__anyquery.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23f8a21f9eee34CAUTIONC72source changed, verdict held
2026-09-19386131a8fba5CAUTIONC72first audit
06

Questions

What is the Anyquery MCP server?

One SQL interface for 60+ tools (e.g., GitHub, Notion, Airtable). Plug into any LLM through MCP.

What tools does Anyquery expose?

12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Anyquery safe to connect to an agent?

With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Anyquery need?

It reads ANYQUERY_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (f8a21f9eee34), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement