mcp-safe-db
Zero-risk, strictly read-only SQL database inspector for AI agents (Claude, Cursor, Antigravity)
GitHub
1
Try this MCPSponsoredDocumentation
π‘οΈ mcp-safe-db
Zero-risk, strictly read-only SQL database inspector for AI agents (Claude Desktop, Antigravity, Cursor, Cline).
Let your AI explore schemas, inspect tables, and run SELECT queries without risking accidental DROP, UPDATE, or DELETE.
β‘ The Problem
Giving an AI assistant database access is risky:
- A hallucinated
UPDATEquery without aWHEREclause can wipe production or local dev data. - Semicolon injection (
SELECT 1; DROP TABLE users;) can execute hidden destructive actions. - Unbounded queries (
SELECT *) blow up context windows and burn API tokens.
mcp-safe-db solves this with an unbreakable Triple-Layer Defense:
- Layer 1 (Parser Guard): Strict regex validation blocks mutation keywords (
INSERT,UPDATE,DROP,ALTER,PRAGMA,ATTACH,LOAD_EXTENSION), multiple statements, and comment bypasses. High limits are capped to 50 rows automatically. - Layer 2 (Connection Lock): SQLite connection is locked with
PRAGMA query_only = ON;. - Layer 3 (OS / C-Engine Lock): Database is opened natively with
{ readOnly: true }. Even if raw SQL bypassed earlier checks, the underlying file handle physically forbids disk writes (attempt to write a readonly database).
π Quickstart
Direct execution via npx
npx mcp-safe-db ./path/to/database.sqlite
π οΈ Configuration
1. Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"safe-db": {
"command": "npx",
"args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
}
}
}
2. Antigravity IDE / Cursor / Cline
Add to your mcp_config.json:
{
"mcpServers": {
"safe-db": {
"command": "npx",
"args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
}
}
}
π§° Available Tools for AI
| Tool | Description | Safe Guard |
|---|---|---|
list_tables | Lists all user tables and views | Filters out internal SQLite tables |
describe_table | Inspects columns, data types, and primary keys | Sanitized table name validation |
sample_table | Returns the first 3 rows of any table | Hard-capped to max 10 rows |
safe_query | Executes arbitrary SELECT queries | Rejects mutations, auto-caps LIMIT |
π§ͺ Testing
npm test
Runs the automated security and safety tests.
π License
MIT Β© 2026
Vibe Coded with π by MrSkele & Antigravity