DatabricksSAFE
Model Context Protocol (MCP) server for Databricks that empowers AI agents to autonomously interact with Unity Catalog metadata. Enables data discovery, lineage analysis, and intelligent SQL execution. Agents explore catalogs/schemas/tables, understand relationships, discover notebooks/jobs, and exe
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://spark.entire.vc/assets/vb-databricks-smart-sql?utmsource=github&utmmedium=readme) [](https://spark.entire.vc/assets/vb-databricks-smart-sql?utmsource=github&utmmedium=readme)
- Motivation
- Overview
- Practical Benefits of UC Metadata for AI Agents
- Available Tools and Features
- Setup
- System Requirements
- Installation
- Permissions Requirements
- Running the Server
- Standalone Mode
- Using with Cursor
- Example Usage Workflow (for an LLM Agent)
- Managing Metadata as Code with Terraform
- Handling Long-Running Queries
- Dependencies
Motivation
Databricks Unity Catalog (UC) allows for detailed documentation of your data assets, including catalogs, schemas, tables, and columns. Documenting these assets thoroughly requires an investment of time. One common question is: what are the practical benefits of this detailed metadata entry?
This MCP server provides a strong justification for that effort. It enables Large Language Models (LLMs) to directly access and utilize this Unity Catalog metadata. The more comprehensively your data is described in UC, the more effectively an LLM agent can understand your Databricks environment. This deeper understanding is crucial for the agent to autonomously construct more intelligent and accurate SQL queries to fulfill data requests.
Overview
This Model Context Protocol (MCP) server is designed to interact with Databricks, with a stro
aed557c21275OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add databricks --env DATABRICKS_CLIENT_SECRET=${DATABRICKS_CLIENT_SECRET} --env DATABRICKS_TOKEN=${DATABRICKS_TOKEN} -- uvx databricks{
"mcpServers": {
"databricks": {
"command": "uvx",
"args": [
"databricks"
],
"env": {
"DATABRICKS_CLIENT_SECRET": "${DATABRICKS_CLIENT_SECRET}",
"DATABRICKS_TOKEN": "${DATABRICKS_TOKEN}"
}
}
}
}Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe_uc_catalog | read | |
describe_uc_schema | read | |
describe_uc_table | read | |
execute_sql_query | write | |
list_uc_catalogs | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
httpx, python-dotenv, mcp
Gates applied: no_behavioural_pass.
aed557c21275full audit observations/trust-audit/mcp-server/rafaelcartenet__databricks.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | aed557c21275 | SAFE | B | 89 | first audit |
Questions
What is the Databricks MCP server?
Model Context Protocol (MCP) server for Databricks that empowers AI agents to autonomously interact with Unity Catalog metadata. Enables data discovery, lineage analysis, and intelligent SQL execution. Agents explore catalogs/schemas/tables, understand relationships, discover notebooks/jobs, and exe
What tools does Databricks expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Databricks safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Databricks need?
It reads DATABRICKS_CLIENT_SECRET and DATABRICKS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Databricks run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as databricks.
How current is this page?
The grade is for one exact copy of the source (aed557c21275), read on 2026-10-08. The repository is watched and re-audited when it changes.