mcp-safe-db

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude, Cursor, Antigravity)

Documentation

πŸ›‘οΈ mcp-safe-db

License: MIT Node.js 22+ Model Context Protocol

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude Desktop, Antigravity, Cursor, Cline).

Let your AI explore schemas, inspect tables, and run SELECT queries without risking accidental DROP, UPDATE, or DELETE.


⚑ The Problem

Giving an AI assistant database access is risky:

  • A hallucinated UPDATE query without a WHERE clause can wipe production or local dev data.
  • Semicolon injection (SELECT 1; DROP TABLE users;) can execute hidden destructive actions.
  • Unbounded queries (SELECT *) blow up context windows and burn API tokens.

mcp-safe-db solves this with an unbreakable Triple-Layer Defense:

  1. Layer 1 (Parser Guard): Strict regex validation blocks mutation keywords (INSERT, UPDATE, DROP, ALTER, PRAGMA, ATTACH, LOAD_EXTENSION), multiple statements, and comment bypasses. High limits are capped to 50 rows automatically.
  2. Layer 2 (Connection Lock): SQLite connection is locked with PRAGMA query_only = ON;.
  3. Layer 3 (OS / C-Engine Lock): Database is opened natively with { readOnly: true }. Even if raw SQL bypassed earlier checks, the underlying file handle physically forbids disk writes (attempt to write a readonly database).

πŸš€ Quickstart

Direct execution via npx

npx mcp-safe-db ./path/to/database.sqlite

πŸ› οΈ Configuration

1. Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

2. Antigravity IDE / Cursor / Cline

Add to your mcp_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

🧰 Available Tools for AI

ToolDescriptionSafe Guard
list_tablesLists all user tables and viewsFilters out internal SQLite tables
describe_tableInspects columns, data types, and primary keysSanitized table name validation
sample_tableReturns the first 3 rows of any tableHard-capped to max 10 rows
safe_queryExecutes arbitrary SELECT queriesRejects mutations, auto-caps LIMIT

πŸ§ͺ Testing

npm test

Runs the automated security and safety tests.


πŸ“„ License

MIT Β© 2026


Vibe Coded with πŸ’– by MrSkele & Antigravity