Atlas / MCP servers / pgedge / pgEdge Postgres

pgEdge PostgresBLOCK

mcp/pgedge/pgedge-postgres

pgEdge MCP Server. A PostgreSQL MCP server with a Natural Language Agent CLI and Web UI.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
PostgreSQL
Stars
233
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-server.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-cli-client.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-web-client.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-docker.yml?query=branch%3Amain) [](https://github.com/pgEdge/pgedge-postgres-mcp/actions/workflows/ci-docs.yml?query=branch%3Amain)

  • About the pgEdge Postgres MCP Server
  • pgEdge Postgres MCP Server
  • Choosing the Right Solution
  • Best Practices - Querying the Server
  • Installing the MCP Server
  • Quick Start
  • Quickstart Demo with Northwind
  • Deploying on Docker
  • Deploying from Source
  • Testing the MCP Server Deployment
  • Configuring the MCP Server
  • Specifying Configuration Preferences
  • Using Environment Variables to Specify Options
  • [Including Provider Embeddings in a Configuration File](docs/guide/provider_co
Read from source at commit dfe4c1200addOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pgedge-nla-web --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pgedge-nla-web": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
gpt-4read
04

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (12 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.trivy/nla-web.trivyignore.yaml:220
Information disclosure via incorrect .netrc password lookup. Not
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.trivy/postgres-mcp.trivyignore.yaml:305
# auth scheme (Negotiate/Digest/.netrc), a cookie jar, LDAPS, SMB, or
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.trivy/postgres-mcp.trivyignore.yaml:433
Information disclosure via incorrect .netrc password lookup. No
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.trivy/postgres-mcp.trivyignore.yaml:435
--netrc, and no .netrc file exists in this minimal image.
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.trivy/postgres-mcp.trivyignore.yaml:443
invocation does not use --netrc and no .netrc file is present.
Why it matters. touches a credential store
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
web/src/components/ChatInterface.jsx:238
console.log(`[Token Tracker] Recording: ${inputTokens} input, ${outputTokens} output tokens`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
web/src/components/ChatInterface.jsx:383
console.log(`[Compaction] Triggered by token count: ~${estimatedTokens} tokens (threshold: ${TOKEN_COMPACTION_THRESHOLD})`);
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
docs/guide/security_mgmt.md:137
"ANTHROPIC_API_KEY": "sk-ant-actual-key-committed-to-git"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
docs/guide/troubleshooting.md:634
"ANTHROPIC_API_KEY": "sk-ant-your-actual-key-here"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
internal/redact/redact_test.go:23
fakeAnthropicKey = "sk-ant-api03-KKKKLLLLMMMMNNNNOOOOPPPPQQQQRRRR"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.claude/testing-expert/coverage-and-quality.md:162
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.claude/testing-expert/coverage-and-quality.md:534
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.claude/testing-expert/integration-testing.md:526
export TEST_PGEDGE_MCP_SERVER=postgres://postgres:password@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.claude/testing-expert/integration-testing.md:788
TEST_PGEDGE_MCP_SERVER: postgres://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci-server.yml:107
TEST_PGEDGE_POSTGRES_CONNECTION_STRING: "postgres://postgres:postgres@localhost:5432/testdb?sslmode=disable"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/reference/config-examples/tokens.md:72
password: "encrypted-password-base64-string-here"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
examples/helm/pgedge-nla/values.yaml:175
- token: "admin-token-change-me"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser-amd64.yaml
.goreleaser-amd64.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser-arm64.yaml
.goreleaser-arm64.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/tools/query_database_test.go:130
expectsRows   bool // true = use Query(), false = use Exec()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/tools/query_database_test.go:319
map[bool]string{true: "Query()", false: "Exec()"}[tt.expectsRows])
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/stdio-anthropic-chatbot/chatbot.py:237
server_path = os.getenv("PGEDGE_MCP_SERVER_PATH", "../../bin/pgedge-postgres-mcp")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/chat/config.go:85
ServerPath: "../../bin/pgedge-postgres-mcp",

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha dfe4c1200addfull audit observations/trust-audit/mcp-server/pgedge__pgedge-postgres.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06dfe4c1200addBLOCKF49first audit
06

Questions

What is the pgEdge Postgres MCP server?

pgEdge MCP Server. A PostgreSQL MCP server with a Natural Language Agent CLI and Web UI.

What tools does pgEdge Postgres expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is pgEdge Postgres safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (49/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does pgEdge Postgres need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (dfe4c1200add), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement