MrSkelee/mcp-safe-db

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude, Antigravity, Cursor)

TypeScript

1

4 commits

updated Oct 7, 2026

See the code

See what people are saying

SourceMessageScoreDate

mcp-safe-db: A strictly read-only SQL MCP server with engine-level write blocking (r/mcp)

Giving an AI agent access to a local database usually means trusting it not to hallucinate an `UPDATE` without a `WHERE` clause or a `DROP TABLE`. I built **mcp-safe-db** to make database inspection zero-risk for Claude, Cursor, and other MCP clients: * **Engine-level lock**: Enforces SQLite…

1

Oct 7, 2026

README

🛡️ mcp-safe-db

License: MIT Node.js 22+ Model Context Protocol

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude Desktop, Antigravity, Cursor, Cline).

Let your AI explore schemas, inspect tables, and run SELECT queries without risking accidental DROP, UPDATE, or DELETE.


⚡ The Problem

Giving an AI assistant database access is risky:

  • A hallucinated UPDATE query without a WHERE clause can wipe production or local dev data.
  • Semicolon injection (SELECT 1; DROP TABLE users;) can execute hidden destructive actions.
  • Unbounded queries (SELECT *) blow up context windows and burn API tokens.

mcp-safe-db solves this with a Dual-Layer Defense:

  1. Layer 1 (Parser Guard): Strict AST & regex validation blocks mutation keywords, multiple statements, and comment bypasses. High limits are capped to 50 rows automatically.
  2. Layer 2 (Engine Lock): SQLite engine is locked with PRAGMA query_only = ON;. Even if a query bypasses parsing, the database engine physically rejects write operations.

🚀 Quickstart

Direct execution via npx

npx mcp-safe-db ./path/to/database.sqlite

🛠️ Configuration

1. Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

2. Antigravity IDE / Cursor / Cline

Add to your mcp_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

🧰 Available Tools for AI

ToolDescriptionSafe Guard
list_tablesLists all user tables and viewsFilters out internal SQLite tables
describe_tableInspects columns, data types, and primary keysSanitized table name validation
sample_tableReturns the first 3 rows of any tableHard-capped to max 10 rows
safe_queryExecutes arbitrary SELECT queriesRejects mutations, auto-caps LIMIT

🧪 Testing

npm test

Runs the automated security and safety tests.


📄 License

MIT © 2026


Vibe Coded with 💖 by MrSkele & Antigravity

ai-agent
antigravity
claude-desktop
mcp
model-context-protocol
sqlite

MrSkelee/mcp-safe-db

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude, Antigravity, Cursor)

TypeScript

1

4 commits

updated Oct 7, 2026

See the code

See what people are saying

SourceMessageScoreDate

mcp-safe-db: A strictly read-only SQL MCP server with engine-level write blocking (r/mcp)

Giving an AI agent access to a local database usually means trusting it not to hallucinate an `UPDATE` without a `WHERE` clause or a `DROP TABLE`. I built **mcp-safe-db** to make database inspection zero-risk for Claude, Cursor, and other MCP clients: * **Engine-level lock**: Enforces SQLite…

1

Oct 7, 2026

README

🛡️ mcp-safe-db

License: MIT Node.js 22+ Model Context Protocol

Zero-risk, strictly read-only SQL database inspector for AI agents (Claude Desktop, Antigravity, Cursor, Cline).

Let your AI explore schemas, inspect tables, and run SELECT queries without risking accidental DROP, UPDATE, or DELETE.


⚡ The Problem

Giving an AI assistant database access is risky:

  • A hallucinated UPDATE query without a WHERE clause can wipe production or local dev data.
  • Semicolon injection (SELECT 1; DROP TABLE users;) can execute hidden destructive actions.
  • Unbounded queries (SELECT *) blow up context windows and burn API tokens.

mcp-safe-db solves this with a Dual-Layer Defense:

  1. Layer 1 (Parser Guard): Strict AST & regex validation blocks mutation keywords, multiple statements, and comment bypasses. High limits are capped to 50 rows automatically.
  2. Layer 2 (Engine Lock): SQLite engine is locked with PRAGMA query_only = ON;. Even if a query bypasses parsing, the database engine physically rejects write operations.

🚀 Quickstart

Direct execution via npx

npx mcp-safe-db ./path/to/database.sqlite

🛠️ Configuration

1. Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

2. Antigravity IDE / Cursor / Cline

Add to your mcp_config.json:

{
  "mcpServers": {
    "safe-db": {
      "command": "npx",
      "args": ["-y", "mcp-safe-db", "/absolute/path/to/your/database.sqlite"]
    }
  }
}

🧰 Available Tools for AI

ToolDescriptionSafe Guard
list_tablesLists all user tables and viewsFilters out internal SQLite tables
describe_tableInspects columns, data types, and primary keysSanitized table name validation
sample_tableReturns the first 3 rows of any tableHard-capped to max 10 rows
safe_queryExecutes arbitrary SELECT queriesRejects mutations, auto-caps LIMIT

🧪 Testing

npm test

Runs the automated security and safety tests.


📄 License

MIT © 2026


Vibe Coded with 💖 by MrSkele & Antigravity

ai-agent
antigravity
claude-desktop
mcp
model-context-protocol
sqlite