SmartDBCAUTION
Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB,DM8,Oracle,not only provides basic database connection such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](README-zh.md) [](README.md) [](https://mseep.ai/app/wenb1n-dev-smartdb-mcp)
SmartDB is a universal database gateway that implements the Model Context Protocol (MCP) server interface. This gateway allows MCP-compatible clients to connect and explore different databases.
Compared to similar products, SmartDB not only provides basic database connection and exploration capabilities but also adds advanced features such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection, making database management and maintenance more secure and intelligent.
Currently Supported Databases
Tool List
bd6848f1bee0OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add SmartDB_MCP --env ACCESS_TOKEN_EXPIRE_MINUTES=${ACCESS_TOKEN_EXPIRE_MINUTES} --env CLIENT_SECRET=${CLIENT_SECRET} --env OAUTH_USER_NAME=${OAUTH_USER_NAME} --env OAUTH_USER_PASSWORD=${OAUTH_USER_PASSWORD} -- uvx SmartDB_MCP{
"mcpServers": {
"SmartDB_MCP": {
"command": "uvx",
"args": [
"SmartDB_MCP"
],
"env": {
"ACCESS_TOKEN_EXPIRE_MINUTES": "${ACCESS_TOKEN_EXPIRE_MINUTES}",
"CLIENT_SECRET": "${CLIENT_SECRET}",
"OAUTH_USER_NAME": "${OAUTH_USER_NAME}",
"OAUTH_USER_PASSWORD": "${OAUTH_USER_PASSWORD}"
}
}
}
}Exposed tools (18)
18 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
创建用户 | read | 创建新用户账户 |
创建角色 | read | 创建新角色 |
删除用户 | read | 删除用户账户 |
删除角色 | read | 删除角色 |
数据备份 | read | 执行数据备份 |
数据库写入 | read | 写入数据库数据 |
数据库删除 | read | 删除数据库数据 |
数据库管理 | read | 管理数据库结构 |
数据库读取 | read | 读取数据库数据 |
普通用户 | read | 基本的系统使用权限 |
查看用户 | read | 查看用户列表和详情 |
查看角色 | read | 查看角色列表和详情 |
系统日志 | read | 查看系统日志 |
系统管理员 | read | 可以管理用户、角色和基本系统设置 |
系统配置 | read | 管理系统配置 |
编辑用户 | read | 修改用户信息 |
编辑角色 | read | 修改角色信息 |
超级管理员 | read | 拥有系统所有权限,可以管理所有用户和角色 |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (3)
.env
.env
mcp, python-dotenv, starlette, uvicorn, PyJWT, sqlalchemy, pymysql, psycopg2-binary
Gates applied: no_behavioural_pass.
bd6848f1bee0full audit observations/trust-audit/mcp-server/wenb1n-dev__smartdb.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | bd6848f1bee0 | CAUTION | B | 86 | first audit |
Questions
What is the SmartDB MCP server?
Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB,DM8,Oracle,not only provides basic database connection such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection
What tools does SmartDB expose?
18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SmartDB safe to connect to an agent?
With care. The audit graded it B (86/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does SmartDB need?
It reads ACCESS_TOKEN_EXPIRE_MINUTES, CLIENT_SECRET, OAUTH_USER_NAME, OAUTH_USER_PASSWORD, REFRESH_TOKEN_EXPIRE_DAYS and TOKEN_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SmartDB run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as SmartDB_MCP.
How current is this page?
The grade is for one exact copy of the source (bd6848f1bee0), read on 2026-10-07. The repository is watched and re-audited when it changes.