Credit Risk Copilot
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Credit Risk CopilotWhat's the total exposure by credit rating?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Credit Risk Copilot
A natural-language interface to a credit risk database. A user asks a question in English. The service returns a validated answer, a chart, and the SQL it ran.
The point of the project is not the SQL generation. The point is the boundary that decides which SQL is allowed to run.
Status
Scaffolded 2026-08-05. No agent yet. No database yet. The preflight check runs.
Related MCP server: AI SQL Agent MCP Server
Requirements
Need | Version | State on this machine |
Python | 3.12 | installed |
Docker Desktop | any current | installed |
Terraform | 1.x | not installed |
AWS CLI | v2 | not installed |
Use Python 3.12, not 3.13. The 3.13 interpreter is ahead of the ML ecosystem, and a package that ships compiled wheels can lag the interpreter by a year.
How to run it
Create the virtual environment:
py -3.12 -m venv .venvActivate it:
.venv\Scripts\activate.batUse the
.batfile. PowerShell blocksActivate.ps1under the default execution policy.Copy the example environment file:
copy .env.local.example .env.localOpen
.env.localand setDEEPSEEK_API_KEY.Run the preflight check:
py -3.12 -m app.doctorThe check imports only the standard library, so it runs before step 6.
Install the dependencies:
pip install -r requirements.txt
Environment variables
.env.local holds every secret. The file is gitignored. Never commit it. If a key reaches a
commit, rotate the key, because removal of the commit does not undo the exposure.
Variable | Required | Purpose |
| yes, for DeepSeek | The API key |
| no | Defaults to |
| no |
|
| no | The local fallback. Needs no key |
| yes | The Postgres connection string |
| no | Tracing. The app runs without it |
The model names changed. DeepSeek retired deepseek-chat and deepseek-reasoner on
2026-07-24. Calls to those names no longer route anywhere. Use deepseek-v4-flash or
deepseek-v4-pro. Both app/doctor.py and app/llm/client.py refuse a retired name and say why.
The architecture rule
app/guardrails/sql_check.py runs on the tool side of the MCP boundary. The agent never calls it.
The agent writes SQL. The MCP tool owns the database connection. The tool validates the SQL before it executes anything. This order matters: a check inside the agent's own code path is skipped by any input that redirects the agent, so such a check is a suggestion and not a control.
The full reasoning is in brain/decisions/2026-08-05-sql-guardrails-live-behind-the-mcp-boundary.md.
What the guardrail refuses
Rule | Reason |
Anything except one | A write reaches the database only through a migration |
A table absent from the allowlist | A new table is denied by default, not allowed by oversight |
A column absent from the allowlist | Column-level control, not table-level |
| The caller must name the columns it needs |
A missing or oversized | One question cannot return the whole table |
Layout
app\
doctor.py preflight check, standard library only
llm\client.py one factory for DeepSeek and Ollama
guardrails\ SQL validation, called by the tool, never by the agentCost
deepseek-v4-flash costs $0.14 per million input tokens on a cache miss. A cache hit costs
$0.0028 per million, which is a 98% discount.
The schema prompt is identical on every call. Put the schema at the front of the prompt and never reorder it, so every call after the first is a cache hit.
Related notes
brain/projects/credit-risk-copilot.md- status, open questions, and the logbrain/decisions/2026-08-05-sql-guardrails-live-behind-the-mcp-boundary.mdbrain/decisions/2026-08-05-python-for-credit-risk-copilot.md
This server cannot be deployed
Maintenance
Related MCP Connectors
Ask questions in plain language, get answers from your business database. No SQL required.
Ask data questions in natural language. Get SQL, insights, and charts from your databases.
Ask business questions in plain English. Get instant answers from your database, no SQL needed.
Query PostgreSQL databases in plain English — LLM-generated, safety-validated SQL.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables natural language querying of SQL databases with robust safety guarantees including read-only enforcement, AST validation, and row caps.-
- AlicenseNot gradedqualityBmaintenanceLets AI clients ask natural-language questions about a SQL database with production-safe guardrails, schema grounding, and read-only enforcement.MIT
- FlicenseNot gradedqualityCmaintenanceEnables secure, read-only analytical querying of financial data through natural language, with built-in SQL injection defense and automatic query repair.-
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to assess credit default risk, run what-if scenarios, and evaluate portfolios through natural language, backed by an explainable XGBoost model.-