AnyqueryCAUTION
One SQL interface for 60+ tools (e.g., GitHub, Notion, Airtable). Plug into any LLM through MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://anyquery.dev) [](https://github.com/julien040/anyquery/issues) [](https://anyquery.dev/integrations/) [](https://anyquery.dev/queries) [](https://pkg.go.dev/github.com/julien040/anyquery/namespace) [](https://archestra.ai/mcp-catalog/julien040__anyquery)
Sponsored by
Fluxion AI - Reliable, cost-efficient access to GPT, Claude, and other leading AI models<
f8a21f9eee34OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add anyquery-website --env ANYQUERY_PASSWORD=${ANYQUERY_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"anyquery-website": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANYQUERY_PASSWORD": "${ANYQUERY_PASSWORD}"
}
}
}
}Exposed tools (12)
11 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
crypto | read | Hashing, encoding and decoding data |
define | read | User-defined functions and dynamic sql |
fileio | write | Read and write files |
fuzzy | read | Fuzzy string matching and phonetics |
ipaddr | read | IP address manipulation |
math | read | Math functions |
regexp | read | Regular expressions |
stats | read | Math statistics |
text | read | String functions and Unicode |
time | read | High-precision date/time |
uuid | read | Universally Unique IDentifiers |
vsv | read | CSV files as virtual tables |
Trust audit
CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (12 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
bun.lockb
to http://127.0.0.1:5566
to http://127.0.0.1:5566
const staticBvar100 = "vtg10vtg11vtg12vtg13vtg14vtg15vtg16vtg17vtg18vtg19vtg20vtg21vtg22vtg23vtg24vtg25vtg26vtg27vtg28vtg29vtg30vtg31vtg32vtg33vtg34vtg35vtg36vtg37vtg38vtg39vtg40vtg41vtg42vtg43vtg44vt
fmt.Println("🧑💻 To develop, launch `anyquery --dev` in developer mode with the flag --dev").goreleaser.yaml
.ignore
.goreleaser.yaml
.goreleaser.yaml
.goreleaser.yaml
"/etc/passwd?/../../../../../../../allowed/decoy",
"/etc/passwd#/../../../../../../../allowed/decoy",
mustError(t, "file:///etc/passwd?/../../allowed/x")
"/allowed/../../../etc/passwd?/../../../../../../../allowed/decoy",
"/allowed/../../../etc/passwd#/../../../../../../../allowed/decoy",
if err := checkSrc(r, "http://169.254.169.254/"); err != nil {if err := checkSrc(denied, "http://169.254.169.254/latest/meta-data/"); err == nil {_, err := conn.ExecContext(ctx, "CREATE VIRTUAL TABLE meta USING csv_reader('http://169.254.169.254/latest/meta-data/')")`--allow-remote` is all-or-nothing: there is no IP or SSRF filtering underneath it (no loopback/RFC1918 blocking), only a scheme check. When enabled, the server can again reach internal addresses and
if err := checkSrc(r, "http://169.254.169.254/"); err != nil {if err := checkSrc(denied, "http://169.254.169.254/latest/meta-data/"); err == nil {_, err := conn.ExecContext(ctx, "CREATE VIRTUAL TABLE meta USING csv_reader('http://169.254.169.254/latest/meta-data/')")drizzle-kit, drizzle-orm, mysql2
@iarna/toml, @types/bun
@astrojs/alpinejs, @astrojs/check, @astrojs/sitemap, @astrojs/starlight, @astrojs/starlight-tailwind, @tailwindcss/vite, @types/alpinejs, alpinejs
Gates applied: no_behavioural_pass.
f8a21f9eee34full audit observations/trust-audit/mcp-server/julien040__anyquery.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | f8a21f9eee34 | CAUTION | C | 72 | source changed, verdict held |
| 2026-09-19 | 386131a8fba5 | CAUTION | C | 72 | first audit |
Questions
What is the Anyquery MCP server?
One SQL interface for 60+ tools (e.g., GitHub, Notion, Airtable). Plug into any LLM through MCP.
What tools does Anyquery expose?
12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Anyquery safe to connect to an agent?
With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Anyquery need?
It reads ANYQUERY_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (f8a21f9eee34), read on 2026-09-23. The repository is watched and re-audited when it changes.