Atlas / MCP servers / ralforion / OrionBelt

OrionBeltCAUTION

mcp/ralforion/orionbelt-1

Ontology-based MCP server that analyzes database schemas (PostgreSQL, Snowflake, ClickHouse, Dremio) and generates RDF/OWL ontologies with SQL mappings for fan-trap-free Text-to-SQL.

Verdict
CAUTION
Grade
C
Trust score
80 /100
Exposed tools
—
Transport
stdio · streamable-http
License
NOASSERTION
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

OrionBelt® Analytics

The Ontology-based MCP server for your Text-2-SQL convenience.

[](https://github.com/ralforion/orionbelt-analytics/releases) [](https://www.python.org/downloads/) [](https://github.com/ralforion/orionbelt-analytics/blob/main/LICENSE) [](https://github.com/jlowin/fastmcp) [](https://www.w3.org/OWL/)

[](https://cloud.google.com/bigquery) [](https://www.postgresql.org) [](https://www.snowflake.com) [](https://clickhouse.com) [](https://www.dremio.com) [](https://www.databricks.com) [](https://duckdb.org) [](https://www.mysql.com)

[![Docker Hub](https://img.shields.io/docker/v/ralforion/orionbelt-analytics?logo=docker&logoColor=white

Read from source at commit 76109eafeb82OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add orionbelt-analytics -- None orionbelt-analytics==2.1.1
03

Trust audit

CAUTIONgrade C · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (14)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/drivers/postgresql.py:78
f"postgresql://{safe_username}:{safe_password}@{host}:{port}/{database}"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_sparql_federation.py:24
"SELECT * WHERE { SERVICE <http://10.0.0.1/sparql> { ?s ?p ?o } }",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_sparql_federation.py:78
yield f"http://127.0.0.1:{server.server_address[1]}/sparql"
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/configuration.md:372
- **File permissions**: Restrict `.env` to owner-only access: `chmod 600 .env`
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/configuration.md:523
- **Access token**: Generate a personal access token in User Settings > Developer > Access Tokens. Tokens can be scoped to specific permissions.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/configuration.md:531
- **Access denied**: Check username, password, and user privileges. Grant access with `GRANT ALL ON mydb.* TO 'user'@'%';` and `FLUSH PRIVILEGES;`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/tools-reference.md:108
- Credentials are read from environment variables (e.g., `POSTGRES_HOST`, `SNOWFLAKE_ACCOUNT`), not passed as parameters
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/tools-reference.md:763
- **Credential isolation** -- database credentials are read from environment variables, never passed as tool parameters
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/configuration.md:285
| `SESSIONLESS_FALLBACK` | `sole_session` | What a call with neither an MCP session nor a `connection` handle resolves to: `sole_session` (the only live session opened without a transport session, if
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/tools-reference.md:82
3. The only live session that was itself opened without a transport session, if there is exactly one. This forgives a model that drops its handle on a single-user server. A session that belongs to a t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/tools-reference.md:764
- **Session isolation** -- each user session keeps its own current schema and ontology state (active or custom-loaded ontology, applied names, OBQC validator). Sessions on the same database share what
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 76109eafeb82full audit observations/trust-audit/mcp-server/ralforion__orionbelt-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0876109eafeb82CAUTIONC80first audit
05

Questions

What is the OrionBelt MCP server?

Ontology-based MCP server that analyzes database schemas (PostgreSQL, Snowflake, ClickHouse, Dremio) and generates RDF/OWL ontologies with SQL mappings for fan-trap-free Text-to-SQL.

Is OrionBelt safe to connect to an agent?

With care. The audit graded it C (80/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does OrionBelt need?

It reads CLICKHOUSE_PASSWORD, DREMIO_PASSWORD, MCP_MASTER_PASSWORD, POSTGRES_PASSWORD and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OrionBelt run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as orionbelt-analytics.

How current is this page?

The grade is for one exact copy of the source (76109eafeb82), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement