Atlas / MCP servers / stuzero / Pg-Mcp

Pg-McpSAFE

mcp/stuzero/pg-mcp

None

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
MIT
Stars
541
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for PostgreSQL databases with enhanced capabilities for AI agents.

More info on the pg-mcp project here:

https://stuzero.github.io/pg-mcp/

Overview

PG-MCP is a server implementation of the Model Context Protocol for PostgreSQL databases. It provides a comprehensive API for AI agents to discover, connect to, query, and understand PostgreSQL databases through MCP's resource-oriented architecture.

This implementation builds upon and extends the reference Postgres MCP implementation with several key enhancements:

  1. Full Server Implementation: Built as a complete server with SSE transport for production use
  2. Multi-database Support: Connect to multiple PostgreSQL databases simultaneously
  3. Rich Catalog Information: Extracts and exposes table/column descriptions from the database catalog
  4. Extension Context: Provides detailed YAML-based knowledge about PostgreSQL extensions like PostGIS and pgvector
  5. Query Explanation: Includes a dedicated tool for analyzing query execution plans
  6. Robust Connection Management: Proper lifecycle for database connections with secure connection ID handling

Features

Connection Management

  • Connect Tool: Register PostgreSQL connection strings and get a secure connection ID
  • Disconnect Tool: Explicitly close database connections when done
  • Connection Pooling: Efficient connection management with pooling

Query Tools

  • pg_query: Execute read-only SQL queries using a connection ID
  • pg_explain: Analyze query execution plans in JSON format

Schema Discovery Resources

  • List schemas with descriptions
  • List tables with descriptions and row counts
  • Get column details with data types and descriptions
  • View table constraints and inde
Read from source at commit c304ec3c4081OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pg-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- uvx pg-mcp
claude-desktop
{
  "mcpServers": {
    "pg-mcp": {
      "command": "uvx",
      "args": [
        "pg-mcp"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
connectread
disconnectread
pg_explainread
pg_metadataread
pg_queryread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
example-clients/claude_cli.py:33
result = codecs.decode(sql_query, 'unicode_escape')
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
example-clients/gemini-agent-cli.py:170
unescaped_sql_query = codecs.decode(sql_query, 'unicode_escape')

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha c304ec3c4081full audit observations/trust-audit/mcp-server/stuzero__pg-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29c304ec3c4081SAFEB89first audit
06

Questions

What is the Pg-Mcp MCP server?

None

What tools does Pg-Mcp expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pg-Mcp safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Pg-Mcp need?

It reads ANTHROPIC_API_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (c304ec3c4081), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement