Atlas / MCP servers / zhaoxingpeng / DBJavaGenix

DBJavaGenixCAUTION

mcp/zhaoxingpeng/dbjavagenix

面向 Java 后端开发的智能数据库代码生成工具:基于 MCP 解析 MySQL 等数据库结构与关系,生成 Entity、DAO、Service、Controller 等分层代码,并支持模板扩展、规范校验与依赖管理。

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
18 16r · 2w · 0d
Transport
stdio
License
NOASSERTION
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/zhaoxingpeng-dbjavagenix)

把"用 LLM 看着数据库做反向工程"做成一件可重复、可审计的事。 Skills 定义"怎么做" · MCP 提供"能做什么" · MCP Apps 让结果"看得见"。

[](https://github.com/ZhaoXingPeng/DBJavaGenix/actions/workflows/ci.yml)

graph LR
Client[Claude Desktop / Cursor / Cherry] -->|Skill 加载| Skills
Skills[".claude/skills/java-codegen-from-dbspringboot-migration"]
Skills -->|按需调用| MCP

subgraph MCP[MCP Server 34 工具]
direction TB
DB[db_* 连接 / 查询 / 描述]
Atom[codegen_build_contextcodegen_render_entity/dao/service/controller/dto/mapper]
Graph[schema_topo_orderschema_cluster_tablesschema_check_cycles]
AI[ai_infer_business_namesai_recommend_templateai_summarize_schema]
Vis[db_render_er_diagram]
Obs[server_metrics / server_healthai_metrics / search_tools]
end

MCP -->|返回 _meta| Apps[MCP Apps 渲染]
Apps -->|mermaid / dashboard / code-diff / tree| Client
MCP -->|读取| Data[MySQL / PostgreSQL / SQLite + Mustache templates]

它解决什么问题

把数据库表反向生成成 Spring Boot 工程 (Entity/DAO/Service/Controller/DTO/Mapper) 不是新东西 —— EasyCode、MyBatis-Plus Generator、Renren-generator 都做了多年。LLM 时代的区别在于:

快速开始

Docker (推荐)

docke
Read from source at commit 050750ea5212OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dbjavagenix-mcp-server --env AI_API_KEY=${AI_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DBJAVAGENIX_TEST_DB_PASSWORD=${DBJAVAGENIX_TEST_DB_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dbjavagenix-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AI_API_KEY": "${AI_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DBJAVAGENIX_TEST_DB_PASSWORD": "${DBJAVAGENIX_TEST_DB_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (18)

16 read · 2 write · 0 destructive.

ToolRiskDescription
codegen_render_entityreadd
db_codegen_analyzereadAnalyze database table structure for code generation with template context
db_connect_testwriteTest database connection and create connection session
db_disconnectreadClose an existing database connection session
db_query_databasesreadList all databases on the server
db_query_executewriteExecute custom SQL query (SELECT only for safety)
db_query_table_existsreadCheck if a table exists in the database
db_query_tablesreadList all tables in a specific database
db_table_columnsreadGet detailed column information for a table
db_table_describereadGet complete table structure information including columns, types, constraints
db_table_foreign_keysreadGet foreign key relationships for a table
db_table_indexesreadGet index information for a table
db_table_primary_keysreadGet primary key information for a table
duplicatereadtest
search_toolsreadd
springboot_analyze_dependenciesreadAnalyze project dependencies and generate intelligent recommendations for code generation
springboot_read_configreadRead Spring Boot project configuration (YAML/Properties/Bootstrap) and infer base package
springboot_validate_projectreadValidate SpringBoot project structure and dependencies before code generation
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (1 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (6)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/dbjavagenix/database/observability_tools.py:90
__import__(mod_name)
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/unit/test_config.py:31
"mysql://reader:p%[email protected]/app?charset=utf8mb4",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/unit/test_config.py:40
"postgresql://reader:p%[email protected]/app",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio, pytest-cov, ruff, mypy, pre-commit
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, pydantic, sqlalchemy, pymysql, psycopg2-binary, PyYAML, python-dotenv, pystache
Why it matters. 13 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
docs/design/dbjavagenix-architecture.png
docs/design/dbjavagenix-architecture.png
Why it matters. 3925427 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 050750ea5212full audit observations/trust-audit/mcp-server/zhaoxingpeng__dbjavagenix.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08050750ea5212CAUTIONB87first audit
06

Questions

What is the DBJavaGenix MCP server?

面向 Java 后端开发的智能数据库代码生成工具:基于 MCP 解析 MySQL 等数据库结构与关系,生成 Entity、DAO、Service、Controller 等分层代码,并支持模板扩展、规范校验与依赖管理。

What tools does DBJavaGenix expose?

18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is DBJavaGenix safe to connect to an agent?

With care. The audit graded it B (87/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does DBJavaGenix need?

It reads AI_API_KEY, ANTHROPIC_API_KEY and DBJAVAGENIX_TEST_DB_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does DBJavaGenix run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as dbjavagenix-mcp-server at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (050750ea5212), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement