database-sentinel
Related Servers
Alternatives to database-sentinel
- AlicenseAqualityCmaintenanceMCP server that lets AI coding agents (Claude Code, Cursor, Cline) audit Supabase projects for security misconfigurations AND apply the fixes — without leaving the agent. Tools: audit_project, list_findings, preview_fix (BEGIN/ROLLBACK safety), apply_fix (with confirmation), apply_all_fixes (transactional bulk). Closes the audit-fix loop entirely in the agent — other Supabase scanners only report.58 npm1MIT
- AlicenseAqualityAmaintenanceProvides an AI agent with read-only PostgreSQL access, enabling schema browsing, foreign-key exploration, column search across tables, capped SELECT queries, and offline data dictionary export while rejecting write operations.99 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables safe, read-only SQL exploration and debugging on Supabase Edge Functions, respecting user JWTs. It inspects schemas, explains query plans, proposes RLS policies, and runs guarded queries without destructive operations.MIT
Related Servers
- FlicenseAqualityDmaintenanceAudits PostgreSQL/Supabase schemas for security issues like missing RLS, permissive policies, and sensitive data exposure during AI conversations.3-
- AlicenseAqualityBmaintenanceEnables auditing a Supabase project's security beyond the dashboard's Security Advisor, checking anonymous access, RLS policies, and cross-tenant data leaks via read-only probes and a two-account test.4642 npmMIT
- AlicenseNot gradedqualityBmaintenanceLets coding agents ask whether a Supabase migration is safe to merge: it replays the base branch and working tree into throwaway databases, reports only the findings the change introduces, and proves RLS leaks by querying as anon. Tools are read-only and take profile names instead of connection strings.MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to safely query PostgreSQL by intercepting and auditing every generated SQL statement before it reaches the database, blocking destructive commands like DROP/TRUNCATE, unbounded DELETE/UPDATE statements, stacked queries, and SQL injection probes. It exposes tools for validating query safety and enforcing a strict read-only (SELECT/EXPLAIN) policy.MIT
- AlicenseNot gradedqualityFmaintenancePredeploy security scanner for AI-generated code. 80+ vulnerability patterns across secrets, auth, injection, config, Supabase, and logging. Runs locally, code never leaves your machine. Optional x402 witnessed attestation.62 npmApache 2.0
- FlicenseNot gradedqualityDmaintenanceProvides read-only access to PostgreSQL databases with schema inspection, query execution in multiple formats (JSON, CSV, Markdown), and query history tracking with built-in security features.-
TDQS
Scored across 4 tools
Each tool has a clearly distinct focus: running allowlisted audit queries, introspecting schema metadata, probing anon-key read access, and scanning a repo for secrets. Overlap is minimal, even though run_audit_query and get_schema both touch database information, because their actions and outputs are different.
All names use snake_case and begin with a verb, giving a readable, predictable pattern. Minor structural variation appears in run_audit_query and probe_as_anon, but conventions are not mixed.
Four tools are well-scoped for a focused database-security auditing server. Each tool covers a distinct security check, and none feels redundant or trivial.
The core security-auditing operations are represented: query-based checks, schema inspection, anon access probing, and repo secret scanning. However, there is no tool to list available audit queries, aggregate findings, or inspect other access-control details such as authenticated roles and policies.