
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Safe-by-default SQL guardrails for AI agents. MCP server for Postgres over stdio + Streamable HTTP: parses every statement with a real SQL AST, enforces a per-table access policy, and audits before the query runs.
Safe-by-default SQL guardrails for AI agents. An MCP server that sits between an AI agent (Claude, Cursor, any MCP client) and your Postgres database. It parses every statement with a real SQL AST — not a regex blocklist — enforces a declarative per-table access policy, blocks destructive DML/DDL, and writes an audit row before the query executes.
📖 Full documentation: midplane.ai/docs
No install — npx fetches it on first run. Add this to your MCP client's config
(Claude Code, Claude Desktop, Cursor — they all take this shape):
{
"mcpServers": {
"midplane": {
"command": "npx",
"args": ["-y", "midplane", "server", "--stdio"],
"env": { "DATABASE_URL": "postgres://user:pass@host:5432/db" }
}
}
}
Keep the connection string in that env block rather than on a command line,
where it would leak to ps aux and your shell history. The block still lands in
a plaintext config file, so give Midplane its own least-privilege Postgres role:
it governs which SQL runs, not what the role underneath it can reach.
Out of the box: reads are allowed, writes and DDL are denied, and every query is audited. Nothing to configure to be safe — configure only to open things up.
npx -y midplane init
Connects read-only, introspects your schema, suggests a tenant column, and writes
a validated midplane.policy.yaml. Point the server at it with
MIDPLANE_POLICY_FILE. The non-interactive equivalent for CI is
midplane policy init.
DELETE targeting a table is denied even
when it carries a WHERE, until you opt that table into read_write.DELETE / UPDATE
(no WHERE), and every DROP / TRUNCATE / ALTER, regardless of the
table's access level.SELECT. The same
recursive walk covers subqueries, UNION arms, and JOINs.Worked examples of each, with the exact SQL and the denial message, are in the policy reference and the repository README.
midplane [server] Run the MCP server (--stdio | --http)
midplane init Interactive setup: introspect the DB, write a policy
midplane query ... Send one query through the server as an agent would
midplane doctor Preflight + smoke checks (config, DB, audit, canary)
midplane audit ... Read the local audit log (tail | since | denies | show | stats)
midplane policy ... Author/validate/lint/dry-run a policy file
The audit log is a local SQLite database at ~/.midplane/audit.db (override with
DB_PATH). midplane audit denies answers the question operators actually ask:
what got blocked, and why.
--stdio) — how MCP clients spawn a local server.--http, the default) — serves /mcp on PORT (8080).midplane/midplane, a self-contained image with no Node or
node_modules in it../bin/self-host up from the
repo.Node 22.16+ or 24+ (the audit log uses the node:sqlite builtin), or Bun 1.3+.
npx ships with Node, so there is nothing else to install — no native modules,
no compiler. Below 22.16 the bin refuses to start and tells you why, rather than
failing partway through with a stack trace from whichever dependency happened to
reach a newer builtin first.
Anonymous, on by default, documented in full in
TELEMETRY.md.
No SQL, no table or column names, no identifiers. Disable with
MIDPLANE_TELEMETRY=0 or DO_NOT_TRACK=1.
MIT — see LICENSE. Source at github.com/midplaneai/midplane. Security issues: see SECURITY.md — please don't open a public issue.
FAQs
Safe-by-default SQL guardrails for AI agents. MCP server for Postgres over stdio + Streamable HTTP: parses every statement with a real SQL AST, enforces a per-table access policy, and audits before the query runs.
The npm package midplane receives a total of 211 weekly downloads. As such, midplane popularity was classified as not popular.
We found that midplane demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.