OrionBelt AnalyticsCAUTION
Ontology-based MCP server that analyzes database schemas (PostgreSQL, Snowflake, ClickHouse, Dremio) and generates RDF/OWL ontologies with SQL mappings for fan-trap-free Text-to-SQL.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
OrionBelt® Analytics
The Ontology-based MCP server for your Text-2-SQL convenience.
[](https://github.com/ralforion/orionbelt-analytics/releases) [](https://www.python.org/downloads/) [](https://github.com/ralforion/orionbelt-analytics/blob/main/LICENSE) [](https://github.com/jlowin/fastmcp) [](https://www.w3.org/OWL/)
[](https://cloud.google.com/bigquery) [](https://www.postgresql.org) [](https://www.snowflake.com) [](https://clickhouse.com) [](https://www.dremio.com) [](https://www.databricks.com) [](https://duckdb.org) [](https://www.mysql.com)
[ | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (14)
f"postgresql://{safe_username}:{safe_password}@{host}:{port}/{database}".env.template
.pre-commit-config.yaml
"SELECT * WHERE { SERVICE <http://10.0.0.1/sparql> { ?s ?p ?o } }",yield f"http://127.0.0.1:{server.server_address[1]}/sparql"| `SESSIONLESS_FALLBACK` | `sole_session` | What a call with neither an MCP session nor a `connection` handle resolves to: `sole_session` (the only live session opened without a transport session, if
3. The only live session that was itself opened without a transport session, if there is exactly one. This forgives a model that drops its handle on a single-user server. A session that belongs to a t
- **Session isolation** -- each user session keeps its own current schema and ontology state (active or custom-loaded ontology, applied names, OBQC validator). Sessions on the same database share what
- **File permissions**: Restrict `.env` to owner-only access: `chmod 600 .env`
- **Access token**: Generate a personal access token in User Settings > Developer > Access Tokens. Tokens can be scoped to specific permissions.
- **Access denied**: Check username, password, and user privileges. Grant access with `GRANT ALL ON mydb.* TO 'user'@'%';` and `FLUSH PRIVILEGES;`.
- Credentials are read from environment variables (e.g., `POSTGRES_HOST`, `SNOWFLAKE_ACCOUNT`), not passed as parameters
- **Credential isolation** -- database credentials are read from environment variables, never passed as tool parameters
Gates applied: no_behavioural_pass.
76109eafeb82full audit observations/trust-audit/mcp-server/ralfbecher__orionbelt-analytics.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 76109eafeb82 | CAUTION | B | 83 | first audit |
Questions
What is the OrionBelt Analytics MCP server?
Ontology-based MCP server that analyzes database schemas (PostgreSQL, Snowflake, ClickHouse, Dremio) and generates RDF/OWL ontologies with SQL mappings for fan-trap-free Text-to-SQL.
Is OrionBelt Analytics safe to connect to an agent?
With care. The audit graded it B (83/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does OrionBelt Analytics need?
It reads CLICKHOUSE_PASSWORD, DREMIO_PASSWORD, MCP_MASTER_PASSWORD, POSTGRES_PASSWORD and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OrionBelt Analytics run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as orionbelt-analytics.
How current is this page?
The grade is for one exact copy of the source (76109eafeb82), read on 2026-10-08. The repository is watched and re-audited when it changes.