🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@database-mcp/mysql

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@database-mcp/mysql - npm Package Compare versions

Comparing version
0.2.1
to
0.3.0
+2
-2
package.json
{
"name": "@database-mcp/mysql",
"version": "0.2.1",
"version": "0.3.0",
"description": "MCP server for MySQL with read-only guardrails, row caps, and statement timeouts",

@@ -32,3 +32,3 @@ "license": "MIT",

"dependencies": {
"@database-mcp/core": "^0.2.0",
"@database-mcp/core": "^0.3.0",
"mysql2": "^3.22.6"

@@ -35,0 +35,0 @@ },

+70
-12

@@ -8,5 +8,2 @@ # @database-mcp/mysql

The password comes from the environment or a mounted secret file — never
from the client config:
```json

@@ -21,3 +18,3 @@ {

"MYSQL_USER": "readonly_user",
"MYSQL_PASSWORD": "...",
"MYSQL_PASSWORD": "your-password",
"MYSQL_DATABASE": "mydb"

@@ -30,12 +27,73 @@ }

Alternatives: `MYSQL_PASSWORD_FILE=/run/secrets/mysql_password`
(Docker/K8s-style), a YAML file via `--config` (values support `${VAR}`
expansion), or `--dsn mysql://user@host:3306/db` (inline DSN passwords are
discouraged but redacted if used). `--print-config` shows the resolved
config with the password redacted.
## Configuration
Use whichever method fits your setup. When methods are combined, flags win
over the YAML file, and the YAML file wins over environment variables.
### Environment variables
`MYSQL_HOST`, `MYSQL_PORT`, `MYSQL_USER`, `MYSQL_PASSWORD`,
`MYSQL_DATABASE`, as in the quick start above.
### Mounted secret file (Docker, Kubernetes)
Keeps the password out of the environment and out of every config file.
Point `MYSQL_PASSWORD_FILE` at a file that contains only the password:
```json
"env": {
"MYSQL_HOST": "127.0.0.1",
"MYSQL_USER": "readonly_user",
"MYSQL_PASSWORD_FILE": "/run/secrets/mysql_password",
"MYSQL_DATABASE": "mydb"
}
```
### YAML config file
Keeps the client entry down to two lines. Pass an absolute path, since the
working directory at launch is unpredictable:
```json
"args": ["-y", "@database-mcp/mysql", "--config", "/absolute/path/database-mcp.yaml"]
```
```yaml
# /absolute/path/database-mcp.yaml
connection:
host: 127.0.0.1
port: 3306
user: readonly_user
password: ${MYSQL_PASSWORD} # expanded from the environment at load time
# or read it from a mounted file instead:
# password_file: /run/secrets/mysql_password
database: mydb
guardrails:
readOnly: true
maxRows: 1000
queryTimeoutMs: 30000
```
Never write a literal password into the YAML file. Use `${VAR}` expansion or
`password_file` as shown.
### Connection string
```json
"args": ["-y", "@database-mcp/mysql", "--dsn", "mysql://readonly_user@127.0.0.1:3306/mydb"]
```
Putting the password inside the DSN works but is discouraged. If you do it
anyway, the server redacts it from any log output.
### Checking the result
Run the server with `--print-config` to see exactly what it resolved. The
password always prints as `***`.
## Tools
- **`execute_sql`** `{ sql }` — run a single SQL statement.
- **`search_objects`** `{ table? }` — list tables, or describe one (columns,
- **`execute_sql`** `{ sql }` runs a single SQL statement.
- **`search_objects`** `{ table? }` lists tables, or describes one (columns,
indexes, foreign keys).

@@ -52,3 +110,3 @@

Read-only is enforced in two layers: a conservative SQL guard, plus
`SET SESSION TRANSACTION READ ONLY` on every pooled connection — so writes
`SET SESSION TRANSACTION READ ONLY` on every pooled connection. Writes
smuggled through CTEs are rejected by the server itself.

@@ -55,0 +113,0 @@