Skip to main content
Glama

termalin-web

data_query

Destructive

Run a database query on one of your servers — passwordless. It executes the engine's own client on the host over Termalin's keyless tunnel, using the database's local trust (Postgres peer auth via sudo -u postgres, MySQL/MariaDB unix-socket via sudo mysql, redis-cli, mongosh, sqlite3) — so no database password is needed or stored anywhere. Read-only by default: only SELECT/SHOW-style statements run unless allowWrites is set (full-access keys only). SQL engines return CSV/TSV with a header. For MongoDB pass a shell expression, e.g. db.products.find({}).limit(20).toArray().

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
hostYesServer id from hosts_list
queryYesThe statement / command / expression to run
engineNoDatabase engine on that server (default postgres)
databaseNoDatabase name (for sqlite: the .db file path)
usernameNoSSH login user (defaults to the tunnel's user, else root)
allowWritesNoAllow a non-read statement (full-access keys only; default false)
timeoutSecondsNoMax seconds to wait (default 60). Calls longer than about 90 seconds are usually cut off by the network before they answer — run long jobs in the background instead.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / timeoutSeconds / description
      Previous value: -"Max seconds to wait (default 60, up to 300)"New value: +"Max seconds to wait (default 60). Calls longer than about 90 seconds are usually cut off by the network before they answer — run long jobs in the background instead."
  2. Added

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations mark destructiveHint=true and readOnlyHint=false, and the description reconciles this by explaining the default read-only posture plus the exact escape hatch (allowWrites, full-access keys). It also discloses the auth model (peer auth / unix socket, no password stored) and the return format (CSV/TSV with header), which annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action and mechanism, then layers default behavior and the MongoDB example. The parenthetical auth list is dense but earns its place; the description is a bit long but no sentence is pure filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description carries the return-value burden and does so ('CSV/TSV with a header', MongoDB array expressions). Combined with the auth, default-write, and timeout disclosures, an agent has everything needed to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description adds real value beyond the schema: a concrete MongoDB expression example, the sqlite database-as-file-path convention, and the fact that allowWrites is gated on full-access keys. Only the engine->auth-method mapping is implicit rather than spelled out per value.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Run a database query on one of your servers') and immediately names the mechanism (engine's own client over a keyless tunnel). This clearly distinguishes it from ssh_exec (arbitrary commands) and data_tables (metadata), so an agent can route correctly without opening siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives strong operational context: read-only by default, writes only with allowWrites and full-access keys, and a warning that calls over ~90s get cut off so long jobs should run in background. It stops short of explicitly contrasting with ssh_exec/data_tables as alternatives, so it's clear-context but not full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources