MysqlSAFE
MCP MySQL Server 是一个基于 @modelcontextprotocol/sdk 的 MySQL 工具服务,支持 SQL 查询、表结构获取、连接检测等功能,适用于 AI 代理、自动化工具等场景。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
项目简介
MCP MySQL Server 是一个基于 @modelcontextprotocol/sdk 的 MySQL 工具服务,支持 SQL 查询、表结构获取、连接检测等功能,适用于 AI 代理、自动化工具等场景。
主要功能
- 执行 SQL 查询(SELECT、INSERT、UPDATE、DELETE)
- 获取数据库表结构信息
- 检测数据库连接状态
- SQL 语句和参数安全校验
- 优雅的服务启动与关闭
架构说明
- 入口文件:
src/index.js启动和管理 MCP 服务器实例 - 服务实现:
src/server.js实现 MCP Server,注册工具、处理请求 - 数据库管理:
src/database.js管理 MySQL 连接池、执行 SQL、获取表结构 - 配置管理:
src/config.js支持 .env 环境变量和默认配置 - 安全校验:
src/validators.js校验 SQL 语句和参数,防止危险操作和注入
安装与使用
- 克隆项目
git clone https://github.com/yourname/mcp-mysql-server.git cd mcp-mysql-server
- 安装依赖
npm install
- 配置数据库连接(可选,支持 .env 文件)
DB_HOST=localhost DB_PORT=3306 DB_USER=root DB_PASSWORD=yourpassword DB_NAME=yourdatabase
- 启动服务
node src/index.js
配置说明
- 支持通过环境变量或
.env文件配置数据库和服务参数 - 主要配置项见
src/config.js
主要实现细节
- 使用
mysql2/promise实现高效的连接池和异步 SQL 执行 - 所有 SQL 语句和参数均经过安全校验,防止危险操作和 SQL 注入
- MCP Server 支持三大工具:
execute_sql:执行 SQL 查询get_tables_info:获取所有表及字段结构get_connection_status:检测数据库连接- 优雅处理进程信号,支持平滑关闭
安全性说明
- 禁止 DROP/TRUNCATE/ALTER 等危险操作
- 检查常见 SQL 注入模式
- 限制参数数量,防止滥用
- 禁用多语句执行
在 Cursor 中 验证 开发的 MCP Server 是否能运行
Cursor 添加 MCP Server
通过 Cursor Settings -> MCP Add new global MCP server,可以将 MCP 服务添加为全局可用。这意味着你配置的 MCP 服务将在所有项目中生效。
也可以只针对 项目级别 添加
在项目的 .cursor目录下,新建一个 mcp.json文件进行配置,这样的设置只会对特定项目生效。

2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute_sql | write | 执行SQL查询语句,支持SELECT、INSERT、UPDATE、DELETE操作 |
get_connection_status | read | 获取数据库连接状态 |
get_tables_info | read | 获取数据库表结构信息 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@modelcontextprotocol/sdk, cors, dotenv, express, express-rate-limit, helmet, mysql2, nodemon
Gates applied: no_behavioural_pass.
b59f3f31e985full audit observations/trust-audit/mcp-server/tickhaijun__mysql-26.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | b59f3f31e985 | SAFE | B | 89 | first audit |
Questions
What is the Mysql MCP server?
MCP MySQL Server 是一个基于 @modelcontextprotocol/sdk 的 MySQL 工具服务,支持 SQL 查询、表结构获取、连接检测等功能,适用于 AI 代理、自动化工具等场景。
What tools does Mysql expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mysql safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mysql need?
No credential environment variables were found in its source, so it appears to need none.
How does Mysql run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-mysql-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (b59f3f31e985), read on 2026-10-08. The repository is watched and re-audited when it changes.