Atlas / MCP servers / pgplex / Pgconsole

PgconsoleBLOCK

mcp/pgplex/pgconsole

Minimal Postgres editor for speed, collaboration, and AI

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
7 4r · 1w · 2d
Transport
streamable-http
License
Apache-2.0
Stars
155
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!NOTE] pgplex: The Postgres Toolchain for Humans and Agents - pgconsole · pgschema · pgtui · pgparser Brought to you by Bytebase, open-source database governance platform.

pgconsole is a web-based PostgreSQL editor. Single binary, single config file, no database required. Connect your team to PostgreSQL with access control and audit logging built in.

Installation

Visit https://docs.pgconsole.com/getting-started/quickstart

Prerequisites

  • Node.js 20+

npm

npm install -g @pgplex/pgconsole
pgconsole --config pgconsole.toml

npx

npx @pgplex/pgconsole --config pgconsole.toml

Docker

docker run -p 9876:9876 -v /path/to/pgconsole.toml:/etc/pgconsole.toml pgplex/pgconsole

Run without --config to start in demo mode with a bundled sample database.

Features

SQL Editor

A full-featured SQL workspace for writing, running, editing, and inspecting PostgreSQL, with parser-powered intelligence in the editor.

  • Autocomplete — cont
Read from source at commit d1e5627a3a04OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pgconsole -- npx -y pgconsole
claude-desktop
{
  "mcpServers": {
    "pgconsole": {
      "command": "npx",
      "args": [
        "-y",
        "pgconsole"
      ]
    }
  }
}
03

Exposed tools (7)

4 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
describe_tablereadFull detail for one table/view: columns and types, primary/foreign keys, indexes, constraints, and comments.
explain_queryreadReturn the query plan for a single SELECT statement. With
list_connectionsreadList the Postgres connections this token can access, with the IAM permissions granted on each.
list_objectsreadBrowse a connection\
querywriteRun a read-only statement (SELECT, SHOW, ...) and return the rows. Results are capped at ${MAX_RESULT_ROWS} rows; when capped, \
run_ddldestructiveRun a schema-changing statement (CREATE / ALTER / DROP / GRANT / REVOKE / ...).
write_datadestructiveRun a data-modifying statement (INSERT / UPDATE / DELETE / COPY). Returns affected row count and any RETURNING rows.
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/take-doc-screenshots/SKILL.md:25
curl -s -c cookies.txt -X POST http://localhost:5173/api/auth/login \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
README.md:109
token = "generate-a-long-random-secret"   # openssl rand -hex 32
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/authentication/overview.mdx:26
password = "your-secure-password"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/configuration/config.mdx:460
token = "pgc_mcp_yyyyyyyyyyyyyyyy"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/features/mcp-server.mdx:48
token = "pgc_mcp_yyyyyyyyyyyyyyyy"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pgconsole.example.toml:222
# token = "generate-a-long-random-secret"   # openssl rand -hex 32
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
run_ddl, write_data
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/lib/sql-permissions.ts:1
import { parseSql, type Statement, type Expr } from "../../src/lib/sql/core";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/lib/sql-permissions.ts:2
import { PG_SYSTEM_FUNCTIONS } from "../../src/lib/sql/pg-system-functions";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/services/ai-service.ts:3
import { AIService } from '../../src/gen/ai_connect'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/services/connection-service.ts:3
import { ConnectionService } from "../../src/gen/connection_connect"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/services/query-service.ts:3
import { QueryService } from "../../src/gen/query_connect";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/openai, @ai-sdk/openai-compatible, @base-ui/react, @bufbuild/protobuf, @codemirror/autocomplete, @codemirror/commands
Why it matters. 69 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
@tailwindcss/typography, clsx, gray-matter, highlight.js, markdown-it, next, react, react-dom
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
worker/demo/package.json
@cloudflare/containers, wrangler
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/authentication/overview.mdx:33
email = "[email protected]"  # SSO-only, no password
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/configuration/config.mdx:361
Rules for controlling access to connections. IAM is opt-in: with no `[[iam]]` rules defined, all authenticated users have full access, and enforcement begins once you define the first rule. See [Datab
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/features/database-access-control.mdx:7
<Info>IAM is **opt-in**. With no `[[iam]]` rules defined, every authenticated user has full access to all connections. Enforcement begins the moment you define your first rule — from then on, any user
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/features/database-access-control.mdx:32
- [Authentication](/configuration/config#authentication) must be enabled, and at least one `[[iam]]` rule must be defined; otherwise, all users get full access to all connections
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/features/database-access-control.mdx:112
### Read-Only Access for Everyone, Full Access for DBAs
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/features/database-access-control.mdx:129
# Developers: full access to dev, read-only on staging and prod

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha d1e5627a3a04full audit observations/trust-audit/mcp-server/pgplex__pgconsole.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d1e5627a3a04BLOCKD61first audit
06

Questions

What is the Pgconsole MCP server?

Minimal Postgres editor for speed, collaboration, and AI

What tools does Pgconsole expose?

7 in total: 4 read-only, 1 that write, and 2 that can delete or overwrite (run_ddl, write_data). Every one is listed on this page with its risk.

Is Pgconsole safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Pgconsole need?

No credential environment variables were found in its source, so it appears to need none.

How does Pgconsole run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as pgconsole.

How current is this page?

The grade is for one exact copy of the source (d1e5627a3a04), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement