SQLAlchemyCAUTION
A simple MCP ODBC server using FastAPI, ODBC and SQLAlchemy.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A lightweight MCP (Model Context Protocol) server for ODBC built with FastAPI, pyodbc, and SQLAlchemy. This server is compatible with Virtuoso DBMS and other DBMS backends that implement a SQLAlchemy provider.
Features
- Get Schemas: Fetch and list all schema names from the connected database.
- Get Tables: Retrieve table information for specific schemas or all schemas.
- Describe Table: Generate a detailed description of table structures, including:
- Column names and data types
- Nullable attributes
- Primary and foreign keys
- Search Tables: Filter and retrieve tables based on name substrings.
- Execute Stored Procedures: In the case of Virtuoso, execute stored procedures and retrieve results.
- Execute Queries:
- JSONL result format: Optimized for structured responses.
- Markdown table format: Ideal for reporting and visualization.
Prerequisites
- Install uv:
pip install uv
Or use Homebrew:
brew install uv
- unixODBC Runtime Environment Checks:
- Check installation configuration (i.e., location of key INI files) by running:
odbcinst -j - List available data source names by running:
odbcinst -q -s
- ODBC DSN Setup: Configure your ODBC Data Source Name (
~/.odbc.ini) for the target database. Example for Virtuoso DBMS:
[VOS] Description = OpenLink Virtuoso Driver = /path/to/virtodbcu_r.so Database = Demo Address = localhost:1111 WideAsUTF16 = Yes
- SQLAlchemy URL Binding: Use the format:
virtuoso+pyodbc://user:password@VOS
Installation
Clone this repository:
git clone https://github.com/OpenLinkSoftware/mcp-sqlalchemy-server.git cd mcp-sqlalchemy-server
Environment Variables
Update your .envby overriding the de
93b68b9d6572OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-sqlalchemy-server --env API_KEY=${API_KEY} --env ODBC_PASSWORD=${ODBC_PASSWORD} -- uvx mcp-sqlalchemy-server{
"mcpServers": {
"mcp-sqlalchemy-server": {
"command": "uvx",
"args": [
"mcp-sqlalchemy-server"
],
"env": {
"API_KEY": "${API_KEY}",
"ODBC_PASSWORD": "${ODBC_PASSWORD}"
}
}
}
}Exposed tools (14)
12 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
podbc_describe_table | read | |
podbc_execute_query | write | |
podbc_execute_query_md | write | |
podbc_filter_table_names | read | |
podbc_get_schemas | read | |
podbc_get_tables | read | |
podbc_query_database | read | |
podbc_sparql_func | read | |
podbc_sparql_get_entity_types | read | |
podbc_sparql_get_entity_types_detailed | read | |
podbc_sparql_get_entity_types_samples | read | |
podbc_sparql_get_ontologies | read | |
podbc_spasql_query | read | |
podbc_virtuoso_support_ai | read |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (2)
.env
.env
Gates applied: no_behavioural_pass.
93b68b9d6572full audit observations/trust-audit/mcp-server/openlinksoftware__sqlalchemy.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 93b68b9d6572 | CAUTION | B | 86 | first audit |
Questions
What is the SQLAlchemy MCP server?
A simple MCP ODBC server using FastAPI, ODBC and SQLAlchemy.
What tools does SQLAlchemy expose?
14 in total: 12 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SQLAlchemy safe to connect to an agent?
With care. The audit graded it B (86/100) and found 2 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does SQLAlchemy need?
It reads API_KEY and ODBC_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (93b68b9d6572), read on 2026-10-09. The repository is watched and re-audited when it changes.