PgconsoleBLOCK
Minimal Postgres editor for speed, collaboration, and AI
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!NOTE] pgplex: The Postgres Toolchain for Humans and Agents - pgconsole · pgschema · pgtui · pgparser Brought to you by Bytebase, open-source database governance platform.
pgconsole is a web-based PostgreSQL editor. Single binary, single config file, no database required. Connect your team to PostgreSQL with access control and audit logging built in.
Installation
Visit https://docs.pgconsole.com/getting-started/quickstart
Prerequisites
- Node.js 20+
npm
npm install -g @pgplex/pgconsole pgconsole --config pgconsole.toml
npx
npx @pgplex/pgconsole --config pgconsole.toml
Docker
docker run -p 9876:9876 -v /path/to/pgconsole.toml:/etc/pgconsole.toml pgplex/pgconsole
Run without --config to start in demo mode with a bundled sample database.
Features
SQL Editor
A full-featured SQL workspace for writing, running, editing, and inspecting PostgreSQL, with parser-powered intelligence in the editor.
- Autocomplete — cont
d1e5627a3a04OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pgconsole -- npx -y pgconsole
{
"mcpServers": {
"pgconsole": {
"command": "npx",
"args": [
"-y",
"pgconsole"
]
}
}
}Exposed tools (7)
4 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
describe_table | read | Full detail for one table/view: columns and types, primary/foreign keys, indexes, constraints, and comments. |
explain_query | read | Return the query plan for a single SELECT statement. With |
list_connections | read | List the Postgres connections this token can access, with the IAM permissions granted on each. |
list_objects | read | Browse a connection\ |
query | write | Run a read-only statement (SELECT, SHOW, ...) and return the rows. Results are capped at ${MAX_RESULT_ROWS} rows; when capped, \ |
run_ddl | destructive | Run a schema-changing statement (CREATE / ALTER / DROP / GRANT / REVOKE / ...). |
write_data | destructive | Run a data-modifying statement (INSERT / UPDATE / DELETE / COPY). Returns affected row count and any RETURNING rows. |
Trust audit
BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
curl -s -c cookies.txt -X POST http://localhost:5173/api/auth/login \
token = "generate-a-long-random-secret" # openssl rand -hex 32
password = "your-secure-password"
token = "pgc_mcp_yyyyyyyyyyyyyyyy"
token = "pgc_mcp_yyyyyyyyyyyyyyyy"
# token = "generate-a-long-random-secret" # openssl rand -hex 32
run_ddl, write_data
streamable-http
import { parseSql, type Statement, type Expr } from "../../src/lib/sql/core";import { PG_SYSTEM_FUNCTIONS } from "../../src/lib/sql/pg-system-functions";import { AIService } from '../../src/gen/ai_connect'import { ConnectionService } from "../../src/gen/connection_connect"import { QueryService } from "../../src/gen/query_connect";@ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/openai, @ai-sdk/openai-compatible, @base-ui/react, @bufbuild/protobuf, @codemirror/autocomplete, @codemirror/commands
@tailwindcss/typography, clsx, gray-matter, highlight.js, markdown-it, next, react, react-dom
@cloudflare/containers, wrangler
email = "[email protected]" # SSO-only, no password
Rules for controlling access to connections. IAM is opt-in: with no `[[iam]]` rules defined, all authenticated users have full access, and enforcement begins once you define the first rule. See [Datab
<Info>IAM is **opt-in**. With no `[[iam]]` rules defined, every authenticated user has full access to all connections. Enforcement begins the moment you define your first rule — from then on, any user
- [Authentication](/configuration/config#authentication) must be enabled, and at least one `[[iam]]` rule must be defined; otherwise, all users get full access to all connections
### Read-Only Access for Everyone, Full Access for DBAs
# Developers: full access to dev, read-only on staging and prod
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
d1e5627a3a04full audit observations/trust-audit/mcp-server/pgplex__pgconsole.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d1e5627a3a04 | BLOCK | D | 61 | first audit |
Questions
What is the Pgconsole MCP server?
Minimal Postgres editor for speed, collaboration, and AI
What tools does Pgconsole expose?
7 in total: 4 read-only, 1 that write, and 2 that can delete or overwrite (run_ddl, write_data). Every one is listed on this page with its risk.
Is Pgconsole safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (61/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Pgconsole need?
No credential environment variables were found in its source, so it appears to need none.
How does Pgconsole run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as pgconsole.
How current is this page?
The grade is for one exact copy of the source (d1e5627a3a04), read on 2026-10-07. The repository is watched and re-audited when it changes.