pgEdge PostgresBLOCK
pgEdge MCP Server. A PostgreSQL MCP server with a Natural Language Agent CLI and Web UI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-server.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-cli-client.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-web-client.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-docker.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-docs.yml?query=branch%3Amain)
- About the pgEdge Postgres MCP Server
- pgEdge Postgres MCP Server
- Choosing the Right Solution
- Best Practices - Querying the Server
- Installing the MCP Server
- Quick Start
- Quickstart Demo with Northwind
- Deploying on Docker
- Deploying from Source
- Testing the MCP Server Deployment
- Configuring the MCP Server
- Specifying Configuration Preferences
- Using Environment Variables to Specify Options
- [Including Provider Embeddings in a Configuration File](docs/guide/provider_co
dfe4c1200addOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pgedge-nla-web --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"pgedge-nla-web": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
gpt-4 | read |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (12 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
Information disclosure via incorrect .netrc password lookup. Not
# auth scheme (Negotiate/Digest/.netrc), a cookie jar, LDAPS, SMB, or
Information disclosure via incorrect .netrc password lookup. No
--netrc, and no .netrc file exists in this minimal image.
invocation does not use --netrc and no .netrc file is present.
console.log(`[Token Tracker] Recording: ${inputTokens} input, ${outputTokens} output tokens`);console.log(`[Compaction] Triggered by token count: ~${estimatedTokens} tokens (threshold: ${TOKEN_COMPACTION_THRESHOLD})`);"ANTHROPIC_API_KEY": "sk-ant-actual-key-committed-to-git"
"ANTHROPIC_API_KEY": "sk-ant-your-actual-key-here"
fakeAnthropicKey = "sk-ant-api03-KKKKLLLLMMMMNNNNOOOOPPPPQQQQRRRR"
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
export TEST_PGEDGE_MCP_SERVER=postgres://postgres:password@localhost:5432/postgres
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
TEST_PGEDGE_POSTGRES_CONNECTION_STRING: "postgres://postgres:postgres@localhost:5432/testdb?sslmode=disable"
password: "encrypted-password-base64-string-here"
- token: "admin-token-change-me"
.coderabbit.yaml
.golangci.yml
.goreleaser-amd64.yaml
.goreleaser-arm64.yaml
expectsRows bool // true = use Query(), false = use Exec()
map[bool]string{true: "Query()", false: "Exec()"}[tt.expectsRows])server_path = os.getenv("PGEDGE_MCP_SERVER_PATH", "../../bin/pgedge-postgres-mcp")ServerPath: "../../bin/pgedge-postgres-mcp",
Gates applied: no_behavioural_pass.
dfe4c1200addfull audit observations/trust-audit/mcp-server/pgedge__pgedge-postgres.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | dfe4c1200add | BLOCK | F | 49 | first audit |
Questions
What is the pgEdge Postgres MCP server?
pgEdge MCP Server. A PostgreSQL MCP server with a Natural Language Agent CLI and Web UI.
What tools does pgEdge Postgres expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is pgEdge Postgres safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does pgEdge Postgres need?
It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (dfe4c1200add), read on 2026-10-06. The repository is watched and re-audited when it changes.