Atlas / MCP servers / oceanbase / OceanBase

OceanBaseBLOCK

mcp/oceanbase/oceanbase-1

MCP Server for OceanBase database and its tools

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
134 92r · 30w · 12d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
109
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) Server Collection for OceanBase Ecosystem

English | 简体中文

[](LICENSE) [](https://python.org) [](https://www.typescriptlang.org/)

📖 Project Overview

awesome-oceanbase-mcp is a Model Context Protocol (MCP) server repository specifically designed for the OceanBase ecosystem.

🎯 Mission: Enable AI assistants to interact directly with OceanBase databases and ecosystem components through standardized MCP protocols.

✨ Core Values:

  • 🤖 AI-Friendly: Direct database operations within Claude, ChatGPT and other AI assistants
  • 🔒 Secure & Reliable: Provides safe database access and operation mechanisms
  • 🛠️ Complete Ecosystem: Covers the complete OceanBase product and tool chain
  • 🚀 Ready to Use: Simple configuration to get started

🔍 What is MCP?

The Model Context Protocol (MCP) is an open protocol designed to enable seamless integration between AI applications and external data sources and tools. It provides a standardized way for AI models to access the contextual information and capabilities they need.

🚀 Quick Start

Prerequisites

If you don't have an OceanBase database instance yet, please:

🗂️ MCP Server Collection

This repository provides complete MCP servers for the OceanBase ecosystem:

🔧 MCP Server 📝 Description 📚 Documentation

OceanBase MCP Server Provides secure interaction capabilities

Read from source at commit faa944df9bd5OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add obcloud-mcp-server --env ALLOWED_TOKENS=${ALLOWED_TOKENS} --env OB_CLUSTER_PASSWORD=${OB_CLUSTER_PASSWORD} --env OB_PASSWORD=${OB_PASSWORD} --env OCP_ACCESS_KEY_ID=${OCP_ACCESS_KEY_ID} -- npx -y @oceanbase/[email protected]
claude-desktop
{
  "mcpServers": {
    "obcloud-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@oceanbase/[email protected]"
      ],
      "env": {
        "ALLOWED_TOKENS": "${ALLOWED_TOKENS}",
        "OB_CLUSTER_PASSWORD": "${OB_CLUSTER_PASSWORD}",
        "OB_PASSWORD": "${OB_PASSWORD}",
        "OCP_ACCESS_KEY_ID": "${OCP_ACCESS_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (134)

92 read · 30 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate_tenantread激活备用租户
add_data_to_collectionwrite
add_memorywrite
add_memory_with_profilewrite
ai_completeread
ai_rerankread
call_obshell_sdkread调用 obshell 的 sdk 方法
change_tenant_passwordread修改租户密码
configure_cluster_connectionread
connectwritecreate connection to oceanbase database
create_ai_modelwrite
create_ai_model_endpointwrite
create_backup_policywrite在指定集群中创建备份策略
create_clusterwriteroot_pwd = SYS_PASSWORD
create_collectionwrite
create_oceanbase_performance_reportwrite
create_tenantwrite# Global variable `secure_file_priv` take a while to take effect, so we set it early (right after tenant creation)
delete_all_memoriesdestructive
delete_backup_policydestructive删除指定租户的备份策略
delete_clusterdestructive删除指定命名空间中的OceanBase集群
delete_collectiondestructive
delete_documentsdestructive
delete_memorydestructive
delete_memory_with_profiledestructive
delete_tenantdestructive删除指定租户
delete_user_profiledestructive
diagnosticsreadDiagnose the operational status of a tenant
drop_ai_modeldestructive
drop_ai_model_endpointdestructive
execute_cluster_sqlwrite
execute_sqlwriteExecute an SQL on the OceanBase server.
export_csv_file_from_seekdbread
full_text_searchread
get_ai_model_endpointsread
get_all_obshell_sdk_methodsread获取 obshell 所有可供用户使用的 sdk 方法
get_all_oceanbase_tenantsread
get_all_server_nodesread
get_current_tenantread
get_current_timereadGet current time from OceanBase database.
get_memory_by_idread
get_ob_ash_reportread
get_obshell_sdk_methods_descriptionread获取 obshell 的 sdk 方法的描述
get_oceanbase_alarm_detailread
get_oceanbase_alarmsread
get_oceanbase_cluster_parametersread
get_oceanbase_cluster_server_statsread
get_oceanbase_cluster_serversread
get_oceanbase_cluster_snapshotsread
get_oceanbase_cluster_statsread
get_oceanbase_cluster_tenantsread
get_oceanbase_cluster_unitsread
get_oceanbase_cluster_zonesread
get_oceanbase_inspection_item_last_resultread
get_oceanbase_inspection_overviewread
get_oceanbase_inspection_reportread
get_oceanbase_inspection_report_inforead
get_oceanbase_inspection_tasksread
get_oceanbase_metric_data_with_labelread
get_oceanbase_metric_groupsread
get_oceanbase_obproxy_cluster_detailread
get_oceanbase_obproxy_cluster_parametersread
get_oceanbase_performance_reportread
get_oceanbase_sql_textread
get_oceanbase_tenant_databasesread
get_oceanbase_tenant_detailread
get_oceanbase_tenant_objectsread
get_oceanbase_tenant_parametersread
get_oceanbase_tenant_role_detailread
get_oceanbase_tenant_rolesread
get_oceanbase_tenant_slow_sqlread
get_oceanbase_tenant_top_sqlread
get_oceanbase_tenant_unitsread
get_oceanbase_tenant_user_detailread
get_oceanbase_tenant_usersread
get_oceanbase_zone_serversread
get_registered_ai_modelsread
get_resource_capacityread
get_user_profileread
has_collectionread
hybrid_searchread
import_csv_file_to_seekdbwrite
install_componentwrite安装OceanBase组件, 目前支持ob-operator,ob-dashboard, local-path-provisioner,cert-manager,不支持其他组件,
install_ob_operatorwrite安装ob-operator
install_okctlwrite安装okctl
list_all_clustersread列出所有的OceanBase集群
list_backup_policiesread列出指定集群中的所有备份策略
list_collectionsread
list_databasesreaddescribe databases by teant id
list_instancesreadlist oceanbase instances
list_memoriesread
list_obproxy_clustersread
list_oceanbase_clustersread
list_tenantsreaddescribe tenants by instance id
list_user_profilesread
obcloud-workflowreadobcloud 操作的工作流
obdiag_analyze_logread
obdiag_check_runwrite
obdiag_cluster_listread
obdiag_display_listread
obdiag_display_runwrite
obdiag_gather_logread
oceanbase_hybrid_searchread
oceanbase_text_searchread
oceanbase_vector_searchread
pause_backup_policyread暂停指定租户的备份策略
peek_collectionread
queryreadquery infos from tenant
query_collectionread
replay_tenant_logread回放租户日志
resume_backup_policyread恢复指定租户的备份策略
run_oceanbase_inspectionwrite
scale_clusterread扩缩OceanBase集群,支持添加/调整/删除可用区
scale_tenantread扩缩租户资源,一次只能执行一种类型的扩展操作
search_memoriesread
search_memories_with_profileread
search_oceanbase_documentread
seekdb_memory_deletedestructive
seekdb_memory_insertwrite
seekdb_memory_queryread
seekdb_memory_updatewrite
set_oceanbase_cluster_parameterswrite
set_oceanbase_tenant_parameterswrite
show_backup_policyread查看指定租户的备份策略
show_clusterread显示指定OceanBase集群的概览
show_tenantread显示租户信息
switchover_tenantread切换主备租户
update_backup_policywrite更新指定租户的备份策略
update_clusterwrite更新OceanBase集群,支持CPU/内存/存储的调整
update_collectionwrite
update_componentwrite更新OceanBase组件, 目前支持ob-operator,ob-dashboard, local-path-provisioner,cert-manager,不支持其他组件,
update_memorywrite
update_tenantwrite更新租户信息
upgrade_clusterread升级OceanBase集群,请指定新的镜像
upgrade_tenantread升级租户
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/obcloud_mcp_server/src/functions/request.ts:12
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/okctl_mcp_server/server.py:35
importlib.import_module(f"okctl_mcp_server.tools.{tool_name}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/oceanbase_mcp_server/oceanbase_mcp/server.py:93
logger.warning(f"Invalid token provided: {token[:10]}...")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/oceanbase_mcp_server/oceanbase_mcp/server.py:96
logger.debug(f"Valid token accepted: {token[:10]}...")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_all_memories, delete_backup_policy, delete_cluster, delete_collection, delete_documents, delete_memory, delete_memory_with_profile, delete_tenant, delete_user_profile, drop_ai_model, drop_ai_mo
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/oceanbase_mcp_server/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/ocp_mcp_server/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/seekdb_mcp_server/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/ocp_mcp_server/ocp_mcp/ocp_client.py:70
md5_hash = hashlib.md5(data).hexdigest().upper()
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/seekdb_mcp_server/README.md:296
"url": "http://127.0.0.1:6000/sse"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/seekdb_mcp_server/README.md:307
"url": "http://127.0.0.1:6000/sse"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/seekdb_mcp_server/README.md:313
- URL: `http://127.0.0.1:6000/sse`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/seekdb_mcp_server/README.md:362
"url": "http://127.0.0.1:6000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/seekdb_mcp_server/README.md:373
"url": "http://127.0.0.1:6000/mcp"
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/oceanbase_mcp_server/README.md:7
[<img src="https://cursor.com/deeplink/mcp-install-dark.svg" alt="Install in Cursor">](https://cursor.com/en/install-mcp?name=OceanBase-MCP&config=eyJjb21tYW5kIjogInV2eCIsICJhcmdzIjogWyItLWZyb20iLCAib
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/oceanbase_mcp_server/README_CN.md:6
[<img src="https://cursor.com/deeplink/mcp-install-dark.svg" alt="Install in Cursor">](https://cursor.com/en/install-mcp?name=OceanBase-MCP&config=eyJjb21tYW5kIjogInV2eCIsICJhcmdzIjogWyItLWZyb20iLCAib
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/ocp_mcp_server/ocp_mcp/ocp_tool.py:932
html_content = base64.b64decode(content_base64)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio, pytest-cov, black, isort, mypy, ruff
Why it matters. 7 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, fastmcp, mysql-connector-python, python-dotenv, beautifulsoup4, certifi, requests
Why it matters. 7 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/obcloud_mcp_server/package.json
@modelcontextprotocol/sdk, axios, dayjs, dotenv, http-cookie-agent, mysql2, node-rsa, tough-cookie
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/oceanbase_mcp_server/README.md:46
- [✔️] **Get ASH report** - Generate [Active Session History](https://www.oceanbase.com/docs/common-oceanbase-database-cn-1000000002013776) reports
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/seekdb_mcp_server/README.md:256
cat > .env << EOF
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/seekdb_mcp_server/README.md:265
**Step 2: Load environment variables**
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/seekdb_mcp_server/README.md:322
cat > .env << EOF
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha faa944df9bd5full audit observations/trust-audit/mcp-server/oceanbase__oceanbase-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08faa944df9bd5BLOCKD69first audit
06

Questions

What is the OceanBase MCP server?

MCP Server for OceanBase database and its tools

What tools does OceanBase expose?

134 in total: 92 read-only, 30 that write, and 12 that can delete or overwrite (delete_all_memories, delete_backup_policy, delete_cluster, delete_collection, delete_documents). Every one is listed on this page with its risk.

Is OceanBase safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OceanBase need?

It reads ALLOWED_TOKENS, OB_CLUSTER_PASSWORD, OB_PASSWORD, OCP_ACCESS_KEY_ID, OCP_ACCESS_KEY_SECRET, SEEKDB_PASSWORD and SYS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OceanBase run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @oceanbase/obcloud-mcp-server at 0.0.7.

How current is this page?

The grade is for one exact copy of the source (faa944df9bd5), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement