Atlas / MCP servers / rafaelcartenet / Databricks

DatabricksSAFE

mcp/rafaelcartenet/databricks

Model Context Protocol (MCP) server for Databricks that empowers AI agents to autonomously interact with Unity Catalog metadata. Enables data discovery, lineage analysis, and intelligent SQL execution. Agents explore catalogs/schemas/tables, understand relationships, discover notebooks/jobs, and exe

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://spark.entire.vc/assets/vb-databricks-smart-sql?utmsource=github&utmmedium=readme) [](https://spark.entire.vc/assets/vb-databricks-smart-sql?utmsource=github&utmmedium=readme)

  • Motivation
  • Overview
  • Practical Benefits of UC Metadata for AI Agents
  • Available Tools and Features
  • Setup
  • System Requirements
  • Installation
  • Permissions Requirements
  • Running the Server
  • Standalone Mode
  • Using with Cursor
  • Example Usage Workflow (for an LLM Agent)
  • Managing Metadata as Code with Terraform
  • Handling Long-Running Queries
  • Dependencies

Motivation

Databricks Unity Catalog (UC) allows for detailed documentation of your data assets, including catalogs, schemas, tables, and columns. Documenting these assets thoroughly requires an investment of time. One common question is: what are the practical benefits of this detailed metadata entry?

This MCP server provides a strong justification for that effort. It enables Large Language Models (LLMs) to directly access and utilize this Unity Catalog metadata. The more comprehensively your data is described in UC, the more effectively an LLM agent can understand your Databricks environment. This deeper understanding is crucial for the agent to autonomously construct more intelligent and accurate SQL queries to fulfill data requests.

Overview

This Model Context Protocol (MCP) server is designed to interact with Databricks, with a stro

Read from source at commit aed557c21275OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add databricks --env DATABRICKS_CLIENT_SECRET=${DATABRICKS_CLIENT_SECRET} --env DATABRICKS_TOKEN=${DATABRICKS_TOKEN} -- uvx databricks
claude-desktop
{
  "mcpServers": {
    "databricks": {
      "command": "uvx",
      "args": [
        "databricks"
      ],
      "env": {
        "DATABRICKS_CLIENT_SECRET": "${DATABRICKS_CLIENT_SECRET}",
        "DATABRICKS_TOKEN": "${DATABRICKS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
describe_uc_catalogread
describe_uc_schemaread
describe_uc_tableread
execute_sql_querywrite
list_uc_catalogsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
httpx, python-dotenv, mcp
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha aed557c21275full audit observations/trust-audit/mcp-server/rafaelcartenet__databricks.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08aed557c21275SAFEB89first audit
06

Questions

What is the Databricks MCP server?

Model Context Protocol (MCP) server for Databricks that empowers AI agents to autonomously interact with Unity Catalog metadata. Enables data discovery, lineage analysis, and intelligent SQL execution. Agents explore catalogs/schemas/tables, understand relationships, discover notebooks/jobs, and exe

What tools does Databricks expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Databricks safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Databricks need?

It reads DATABRICKS_CLIENT_SECRET and DATABRICKS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Databricks run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as databricks.

How current is this page?

The grade is for one exact copy of the source (aed557c21275), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement