Atlas / MCP servers / openlinksoftware / SQLAlchemy

SQLAlchemyCAUTION

mcp/openlinksoftware/sqlalchemy

A simple MCP ODBC server using FastAPI, ODBC and SQLAlchemy.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
14 12r · 2w · 0d
Transport
—
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A lightweight MCP (Model Context Protocol) server for ODBC built with FastAPI, pyodbc, and SQLAlchemy. This server is compatible with Virtuoso DBMS and other DBMS backends that implement a SQLAlchemy provider.

Features

  • Get Schemas: Fetch and list all schema names from the connected database.
  • Get Tables: Retrieve table information for specific schemas or all schemas.
  • Describe Table: Generate a detailed description of table structures, including:
  • Column names and data types
  • Nullable attributes
  • Primary and foreign keys
  • Search Tables: Filter and retrieve tables based on name substrings.
  • Execute Stored Procedures: In the case of Virtuoso, execute stored procedures and retrieve results.
  • Execute Queries:
  • JSONL result format: Optimized for structured responses.
  • Markdown table format: Ideal for reporting and visualization.

Prerequisites

  1. Install uv:
pip install uv

Or use Homebrew:

brew install uv
  1. unixODBC Runtime Environment Checks:
  1. Check installation configuration (i.e., location of key INI files) by running: odbcinst -j
  2. List available data source names by running: odbcinst -q -s
  1. ODBC DSN Setup: Configure your ODBC Data Source Name (~/.odbc.ini) for the target database. Example for Virtuoso DBMS:
[VOS]
Description = OpenLink Virtuoso
Driver = /path/to/virtodbcu_r.so
Database = Demo
Address = localhost:1111
WideAsUTF16 = Yes
  1. SQLAlchemy URL Binding: Use the format:
virtuoso+pyodbc://user:password@VOS

Installation

Clone this repository:

git clone https://github.com/OpenLinkSoftware/mcp-sqlalchemy-server.git
cd mcp-sqlalchemy-server

Environment Variables

Update your .envby overriding the de

Read from source at commit 93b68b9d6572OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-sqlalchemy-server --env API_KEY=${API_KEY} --env ODBC_PASSWORD=${ODBC_PASSWORD} -- uvx mcp-sqlalchemy-server
claude-desktop
{
  "mcpServers": {
    "mcp-sqlalchemy-server": {
      "command": "uvx",
      "args": [
        "mcp-sqlalchemy-server"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "ODBC_PASSWORD": "${ODBC_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (14)

12 read · 2 write · 0 destructive.

ToolRiskDescription
podbc_describe_tableread
podbc_execute_querywrite
podbc_execute_query_mdwrite
podbc_filter_table_namesread
podbc_get_schemasread
podbc_get_tablesread
podbc_query_databaseread
podbc_sparql_funcread
podbc_sparql_get_entity_typesread
podbc_sparql_get_entity_types_detailedread
podbc_sparql_get_entity_types_samplesread
podbc_sparql_get_ontologiesread
podbc_spasql_queryread
podbc_virtuoso_support_airead
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (2)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 93b68b9d6572full audit observations/trust-audit/mcp-server/openlinksoftware__sqlalchemy.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0993b68b9d6572CAUTIONB86first audit
06

Questions

What is the SQLAlchemy MCP server?

A simple MCP ODBC server using FastAPI, ODBC and SQLAlchemy.

What tools does SQLAlchemy expose?

14 in total: 12 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SQLAlchemy safe to connect to an agent?

With care. The audit graded it B (86/100) and found 2 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SQLAlchemy need?

It reads API_KEY and ODBC_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (93b68b9d6572), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement