SteampipeCAUTION
Enable AI assistants to explore and query your Steampipe data!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Unlock the power of AI-driven infrastructure analysis with Steampipe! This Model Context Protocol server seamlessly connects AI assistants like Claude to your cloud infrastructure data, enabling natural language exploration and analysis of your entire cloud estate.
Steampipe MCP bridges AI assistants and your infrastructure data, allowing natural language:
- Queries across AWS, Azure, GCP and 100+ cloud services
- Security and compliance analysis
- Cost and resource optimization
- Query development assistance
Works with both local Steampipe installations and Turbot Pipes workspaces, providing safe, read-only access to all your cloud and SaaS data.
Installation
Prerequisites
- Node.js v16 or higher (includes
npx) - For local use: Steampipe installed and running (
steampipe service start) - For Turbot Pipes: A Turbot Pipes workspace and connection string
Configuration
Add Steampipe MCP to your AI assistant's configuration file:
{
"mcpServers": {
"steampipe": {
"command": "npx",
"args": [
"-y",
"@turbot/steampipe-mcp"
]
}
}
}By default, this connects to your local Steampipe installation at postgresql://steampipe@localhost:9193/steampipe. Make sure to run steampipe service start first.
To connect to a Turbot Pipes workspace instead, add your connection string to the args:
{
"mcpServers": {
"steampipe": {
"command": "npx",
"args": [
"-y",
"@turbot/steampipe-mcp",
"postgresql://my_name:[email protected]:9193/abc123"
]
}
}
}AI Assistant Setup
217b919624beOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add steampipe-mcp -- npx -y @turbot/[email protected]
{
"mcpServers": {
"steampipe-mcp": {
"command": "npx",
"args": [
"-y",
"@turbot/[email protected]"
]
}
}
}Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
best_practices | read | Best practices for writing Steampipe SQL queries |
steampipe_plugin_list | read | List all Steampipe plugins installed on the system. Plugins provide access to different data sources like AWS, GCP, or Azure. |
steampipe_plugin_show | read | Get details for a specific Steampipe plugin installation, including version, memory limits, and configuration. |
steampipe_table_list | read | List all available Steampipe tables. Use schema and filter parameters to narrow down results. |
steampipe_table_show | read | Get detailed information about a specific Steampipe table, including column definitions, data types, and descriptions. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (4)
poolConfig.ssl = { rejectUnauthorized: false };"postgresql://my_name:[email protected]:9193/abc123"
const { version } = require('../../package.json');@modelcontextprotocol/sdk, ajv, pg, pg-types, @types/node, @types/pg, shx, typescript
Gates applied: no_behavioural_pass.
217b919624befull audit observations/trust-audit/mcp-server/turbot__steampipe-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 217b919624be | CAUTION | B | 89 | first audit |
Questions
What is the Steampipe MCP server?
Enable AI assistants to explore and query your Steampipe data!
What tools does Steampipe expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Steampipe safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Steampipe need?
No credential environment variables were found in its source, so it appears to need none.
How does Steampipe run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @turbot/steampipe-mcp at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (217b919624be), read on 2026-10-08. The repository is watched and re-audited when it changes.