Skip to main content
Glama
Aderali06

sqlite-mcp-server

read_query

Execute safe read-only SELECT queries against SQLite databases, blocking mutations. Use parameters and row limits to avoid context overflow.

Instructions

Execute a safe, read-only SELECT query against the SQLite database.

Args: query: The SQL SELECT query to execute. Mutation queries (INSERT, UPDATE, DELETE, DROP, etc.) are strictly rejected. params: Optional list of query parameters for prepared statements (? placeholders). max_rows: Maximum number of rows to return (default: 1000). Protects against context overflow. db_path: Optional path to SQLite file. If omitted, uses default database path.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
queryYes
paramsNo
db_pathNo
max_rowsNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden and does disclose the key traits: read-only safety, strict rejection of INSERT/UPDATE/DELETE/DROP, a default 1000-row cap that protects against context overflow, and default database fallback. It omits error/transaction behavior, which keeps it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose sentence is front-loaded and the Args block is compact and scannable. Every line earns its place; the docstring formatting is conventional but not wasteful.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained. Combined with full parameter documentation, mutation rejection, and row-cap rationale, the definition gives an agent enough to call the tool correctly; only edge-case behavior (errors, transactions) is unaddressed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it documents all four parameters with meaning: query semantics plus mutation rejection, params as prepared-statement '?' placeholders, max_rows default and overflow rationale, and db_path default behavior. It stops short of examples or type/format details.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Execute a safe, read-only SELECT query against the SQLite database') and the safety constraint up front. This is clearly distinguishable from the introspection siblings (list_tables, describe_table, get_database_schema), which return metadata rather than rows.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied rather than stated: an agent infers it should call this when it needs actual data. The rejection of mutation queries is a useful negative boundary, but the description never routes the agent to a sibling (e.g., use get_database_schema first to discover tables) or states prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.