Atlas / MCP servers / wenb1n-dev / SmartDB

SmartDBCAUTION

mcp/wenb1n-dev/smartdb

Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB,DM8,Oracle,not only provides basic database connection such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
18 18r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
77
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](README-zh.md) [](README.md) [](https://mseep.ai/app/wenb1n-dev-smartdb-mcp)

SmartDB is a universal database gateway that implements the Model Context Protocol (MCP) server interface. This gateway allows MCP-compatible clients to connect and explore different databases.

Compared to similar products, SmartDB not only provides basic database connection and exploration capabilities but also adds advanced features such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection, making database management and maintenance more secure and intelligent.

Currently Supported Databases

Tool List

Read from source at commit bd6848f1bee0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add SmartDB_MCP --env ACCESS_TOKEN_EXPIRE_MINUTES=${ACCESS_TOKEN_EXPIRE_MINUTES} --env CLIENT_SECRET=${CLIENT_SECRET} --env OAUTH_USER_NAME=${OAUTH_USER_NAME} --env OAUTH_USER_PASSWORD=${OAUTH_USER_PASSWORD} -- uvx SmartDB_MCP
claude-desktop
{
  "mcpServers": {
    "SmartDB_MCP": {
      "command": "uvx",
      "args": [
        "SmartDB_MCP"
      ],
      "env": {
        "ACCESS_TOKEN_EXPIRE_MINUTES": "${ACCESS_TOKEN_EXPIRE_MINUTES}",
        "CLIENT_SECRET": "${CLIENT_SECRET}",
        "OAUTH_USER_NAME": "${OAUTH_USER_NAME}",
        "OAUTH_USER_PASSWORD": "${OAUTH_USER_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (18)

18 read · 0 write · 0 destructive.

ToolRiskDescription
创建用户read创建新用户账户
创建角色read创建新角色
删除用户read删除用户账户
删除角色read删除角色
数据备份read执行数据备份
数据库写入read写入数据库数据
数据库删除read删除数据库数据
数据库管理read管理数据库结构
数据库读取read读取数据库数据
普通用户read基本的系统使用权限
查看用户read查看用户列表和详情
查看角色read查看角色列表和详情
系统日志read查看系统日志
系统管理员read可以管理用户、角色和基本系统设置
系统配置read管理系统配置
编辑用户read修改用户信息
编辑角色read修改角色信息
超级管理员read拥有系统所有权限,可以管理所有用户和角色
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (3)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
src/config/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/config/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, python-dotenv, starlette, uvicorn, PyJWT, sqlalchemy, pymysql, psycopg2-binary
Why it matters. 17 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha bd6848f1bee0full audit observations/trust-audit/mcp-server/wenb1n-dev__smartdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07bd6848f1bee0CAUTIONB86first audit
06

Questions

What is the SmartDB MCP server?

Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB,DM8,Oracle,not only provides basic database connection such as OAuth 2.0 authentication , health checks, SQL optimization, and index health detection

What tools does SmartDB expose?

18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SmartDB safe to connect to an agent?

With care. The audit graded it B (86/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SmartDB need?

It reads ACCESS_TOKEN_EXPIRE_MINUTES, CLIENT_SECRET, OAUTH_USER_NAME, OAUTH_USER_PASSWORD, REFRESH_TOKEN_EXPIRE_DAYS and TOKEN_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SmartDB run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as SmartDB_MCP.

How current is this page?

The grade is for one exact copy of the source (bd6848f1bee0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement