Legion DatabaseSAFE
A server that helps people access and query data in databases using the Legion Query Runner with Model Context Protocol (MCP) in Python.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A server that helps people access and query data in databases using the Legion Query Runner with integration of the Model Context Protocol (MCP) Python SDK.
Start Generation Here
This tool is provided by Legion AI. To use the full-fledged and fully powered AI data analytics tool, please visit the site. Email us if there is one database you want us to support.
End Generation Here
Why Choose Database MCP
Database MCP stands out from other database access solutions for several compelling reasons:
- Unified Multi-Database Interface: Connect to PostgreSQL, MySQL, SQL Server, and other databases through a single consistent API - no need to learn different client libraries for each database type.
- AI-Ready Integration: Built specifically for AI assistant interactions through the Model Context Protocol (MCP), enabling natural language database operations.
- Zero-Configuration Schema Discovery: Automatically discovers and exposes database schemas without manual configuration or mapping.
- Database-Agnostic Tools: Find tables, explore schemas, and execute queries with the same set of tools regardless of the underlying database technology.
- Secure Credential Management: Handles database authentication details securely, separating credentials from application code.
- Simple Deployment: Works with modern AI development environments like LangChain, FastAPI, and others with minimal setup.
- Extensible Design: Easily add custom tools and prompts to enhance functionality for specific use cases.
Whether you're building AI agents that need database access or simply want a unified interface to multiple databases, Database MCP provides a streamlined solution that dramatically reduces development time and complexity.
Features
- Multi-database support - connect to multiple databases simultaneously
- Database access via Legion Query Runner
- Model Context Protocol (MCP) su
35e161773d62OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add database-mcp -- uvx database-mcp
{
"mcpServers": {
"database-mcp": {
"command": "uvx",
"args": [
"database-mcp"
]
}
}
}Exposed tools (10)
8 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe_table | read | Get detailed description of a table including column names and types |
execute_query | write | Execute a SQL query and return results as a markdown table |
execute_query_json | write | Execute a SQL query and return results as JSON |
find_table | read | Find which database contains a specific table |
get_database_info | read | Get detailed information about a database including schema summary |
get_query_history | read | Get the recent query history |
get_table_columns | read | Get column names for a specific table |
get_table_sample | read | Get a sample of data from a table |
get_table_types | read | Get column types for a specific table |
list_databases | read | List all available database connections |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
&& rm -rf /var/lib/apt/lists/*
Gates applied: no_behavioural_pass.
35e161773d62full audit observations/trust-audit/mcp-server/theralabs__legion-database.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 35e161773d62 | SAFE | B | 89 | first audit |
Questions
What is the Legion Database MCP server?
A server that helps people access and query data in databases using the Legion Query Runner with Model Context Protocol (MCP) in Python.
What tools does Legion Database expose?
10 in total: 8 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Legion Database safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Legion Database need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (35e161773d62), read on 2026-10-07. The repository is watched and re-audited when it changes.