litescope
Litescope's MCP server lets AI agents safely inspect, diagnose, diff, migrate, optimize, and (with writes enabled) modify SQLite, Cloudflare D1, and Turso databases with dry-run blast-radius previews and one-call undo.
Read-only tools: list D1 databases, run SELECT/read-only PRAGMA queries with token budgeting, inspect schema, check health/corruption/WAL/fragmentation, diagnose locks, diff databases, plan migrations, recommend indexes, verify backups, fingerprint fleet schemas, triage fleet health, list snapshots.
Write tools (--allow-writes): run mutating SQL dry-run first with exact blast radius; apply writes/migrations with auto-captured rewind token; undo writes in one call; autopilot optimization; snapshot/restore local DBs; rewind D1 via Time Travel; pull/create/delete D1 databases.
MCP extras: canned prompts for workflows, subscribable resources for schema/dictionary/health/locks, interactive MCP Apps views, structured output, and remote Streamable HTTP with bearer token/origin allowlist.
Sources: local SQLite files, D1 (needs CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID), Turso DSNs; all writes are off unless the server starts with --allow-writes.
Provides tools for managing Cloudflare D1 databases, including listing, querying, migrating, rewinding via Time Travel, pulling/pushing, and health checks.
Enables local SQLite database operations such as querying, schema inspection, diffing, migrations, snapshots, restore, autopilot optimization, lock diagnosis, and monitoring.
Supports diff operations between local SQLite databases and Turso remote databases, extending Litescope's data management to Turso.
Litescope
Let AI agents touch production SQLite — safely. Diagnose before the write, rewind after it. For Cloudflare D1, Turso, and local files.
Ask Claude to change your D1 database — and undo it if it's wrong. Every write is dry-run by default with the exact blast radius, and one call away from revert.
Free and open source (AGPL-3.0) — every command, every fleet operation, self-hostable, no license key. The only paid thing is the hosted dashboard we run for you.
Why a tool for SQLite?
"It's just a file — what's there to operate?"
That was true when SQLite was a local dev toy. It isn't anymore. D1, Turso, LiteFS, and Litestream put SQLite in production at fleet scale — thousands of databases, one per tenant. But the tooling never caught up:
sqlite3assumes one database. Production assumes thousands. There's nopg_stat, no APM, no standard way to see from the outside why a database is locked, why WAL is bloating, or which tenant went silent.Embedded means unobservable. The very thing that makes SQLite great — no server — is what leaves you blind in production.
Agents now write to your data. No SQLite tool was built assuming an AI would run the migration. Litescope was.
Postgres has a mature tool for every problem. SQLite has none — so Litescope is one binary for the whole job: fleet observability, file-level superpowers (bisect / rewind / salvage), lock & WAL diagnostics, and a safe interface for agents. Things a generic DB client structurally can't do.
Related MCP server: mcp-sqlite3
MCP — Give Claude direct access to your D1
Claude Code — install the plugin, which brings the MCP server plus five skills (lock doctor, safe writes, migration review, fleet sweep, corruption recovery) that teach the agent how to use it when something is wrong:
/plugin marketplace add croc100/Litescope
/plugin install litescope@litescopeOr just the MCP server, one line (read-only):
claude mcp add litescope -- litescope mcpWith writes + D1 (Litescope still dry-runs every write and captures a rewind point before applying):
claude mcp add litescope \
-e CLOUDFLARE_API_TOKEN=your-token \
-e CLOUDFLARE_ACCOUNT_ID=your-account-id \
-- litescope mcp --allow-writesCursor — one-click:
➕ Add litescope to Cursor
(installs read-only; add --allow-writes and the Cloudflare env vars in
mcp.json to enable writes).
Claude Desktop / Windsurf / any MCP client — add to the config file directly:
{
"mcpServers": {
"litescope": {
"command": "litescope",
"args": ["mcp", "--allow-writes"],
"env": {
"CLOUDFLARE_API_TOKEN": "your-token",
"CLOUDFLARE_ACCOUNT_ID": "your-account-id"
}
}
}
}Also listed in the MCP Registry
as io.github.croc100/litescope.
Then ask Claude things like:
"List my D1 databases"
"Show me the schema of the users table in d1://abc-123"
"Delete every inactive user from d1://prod-db-id" ← dry-run first: shows the
exact blast radius before
you approve the write
"Undo that — put it back the way it was" ← one-call revert via the
rewind_token from the write
"The deploy at 2pm broke something — rewind prod to 1:45pm"
"Diff my local dev.db against d1://prod-db-id and show me the migration SQL"Read-only tools (always available)
Tool | What it does |
| List all D1 databases in the account (UUID, name, DSN) |
| Run a SELECT on any D1 database or local SQLite file |
| Inspect tables, columns, indexes |
| Check for corruption, WAL bloat, fragmentation |
| Schema and row-count diff between any two sources |
| Generate migration SQL + blast-radius analysis |
| Generate migration SQL only (no blast-radius) |
| Performance analysis: missing indexes, full table scans |
| Verify a backup against a reference database |
| Cluster a fleet by schema fingerprint |
| Triage faults across a whole fleet |
| Diagnose |
| List point-in-time snapshots for a local database |
litescope_query enforces token budgeting — max_rows cap + columns
projection + truncation reporting — so a large table never blows the agent's
context window.
Write tools (--allow-writes)
Tool | What it does |
| Mutating SQL — dry-run by default with exact rows affected and blast-radius diff (D1 dry-runs measured on a pulled copy); on apply, captures an undo point first (local: snapshot, D1: Time Travel bookmark) and returns it as a |
| Revert a write in one call using its |
| Apply a migration — same reversible contract as |
| Self-driving optimization (ANALYZE, indexes, VACUUM) — dry-run by default |
| Take a point-in-time backup of a local database |
| Restore a local database from a snapshot |
| Restore a D1 database to a point in time (Time Travel) |
| Download a D1 database to a local SQLite file |
| Create a new D1 database |
| Delete a D1 database (irreversible) |
Write tools are off unless you start the server with --allow-writes, every
write is dry-run by default, and no write commits without an auto-captured undo
point. See the security model for the full boundary — what each
layer protects against, and what it doesn't.
Prompts & Resources
Beyond tools, the MCP server exposes prompts — canned workflows like
diagnose_locked_database, review_migration, safe_optimize, and
health_checkup that chain the tools above into a safe plan — and
resources: a database's schema, data dictionary, live health, and live lock
diagnosis — readable by the agent without spending a tool call, and
subscribable for push updates whenever the underlying file changes. Bind one
with litescope mcp ./app.db, or address any source via
litescope://schema/{source}, litescope://dictionary/{source},
litescope://health/{source}, and litescope://locks/{source}.
The server implements MCP 2026-07-28, the stateless revision: server/discover,
per-request protocol metadata, resultType, caching hints (ttlMs /
cacheScope), and subscriptions/listen streams — alongside tool annotations
(read-only / destructive hints), structured output (structuredContent +
outputSchema) and argument completion. It is dual-era: a client that still
opens with the initialize handshake is served MCP 2025-06-18 unchanged, so
older MCP clients keep working.
Interactive views (MCP Apps)
Four tools answer with an interactive panel rendered inside the conversation,
via the MCP Apps
extension (io.modelcontextprotocol/ui):
Tool | View |
| Lock doctor — verdict, each finding's exact PRAGMA/DSN fix, live lock probe |
| Health panel — integrity, WAL, fragmentation, snapshot cover |
| Blast radius — rows affected per statement, schema impact, rewind token |
| Fleet grid — every database worst-first, with drill-down |
The views are single self-contained documents compiled into the binary. They load nothing from the network, so the host's strictest CSP applies and a database's contents cannot leave the iframe. They never write, either: a button that would apply or undo a write hands the request back to the conversation, because a click inside an embedded panel is not the user approving a production write. A host without the extension gets the same results as text.
Remote / hosted (Streamable HTTP)
By default litescope mcp speaks stdio. For a hosted, remote, or multi-client
setup, serve over the Streamable HTTP transport instead:
litescope mcp --http :7577 --http-token "$LITESCOPE_MCP_TOKEN"POST a JSON-RPC message to the endpoint (/mcp by default). Modern clients are
served statelessly — no session — with each request carrying its own protocol
metadata and the standard MCP-Protocol-Version / Mcp-Method / Mcp-Name
headers, and change notifications arriving on a subscriptions/listen response
stream. Handshake-era clients still get a session via the Mcp-Session-Id
header and a GET SSE stream.
Before exposing it publicly, lock it down: --http-token (or the
LITESCOPE_MCP_TOKEN env var) requires Authorization: Bearer <token> on every
request, and --http-origin allowlists browser Origins (localhost is always
allowed) for DNS-rebinding protection. Without a token the endpoint is open and
the server prints a warning.
D1 — CLI operations
Rewind — D1 Time Travel
# Restore to a previous point in time
litescope rewind d1://DB_ID --to "2h ago"
litescope rewind d1://DB_ID --to "yesterday"
litescope rewind d1://DB_ID --to "2024-01-15T10:30:00Z"
# List available restore points (30-day window + migration timestamps)
litescope rewind list d1://DB_IDPull / Push — sync between D1 and local SQLite
# Download D1 → local (for inspection, backup, or diffing)
litescope d1 pull d1://DB_ID ./snapshot.db
# Upload local → D1 (seed a fresh database or restore from snapshot)
litescope d1 push ./seed.db d1://DB_ID
litescope d1 push ./seed.db d1://DB_ID --drop-existingMigrate — schema changes on D1
# Diff local dev schema against live D1 — generate migration SQL
litescope migrate local.db d1://DB_ID
# Apply a migration directly to D1
litescope migrate apply d1://DB_ID migration.sqlBisect — find which commit broke a D1 database
Binary-search D1 Time Travel to pinpoint the exact snapshot where a query started returning wrong results:
litescope bisect d1://DB_ID \
--good "3d ago" \
--bad now \
--check "SELECT COUNT(*) FROM orders WHERE status = 'paid'" \
--expect "gt:0"Checks gt:0 (greater-than), lt:N, eq:N, or a literal value. Narrows
to the snapshot window where the condition first failed, then lets you
inspect or rewind.
Local SQLite
doctor — one-shot checkup
litescope doctor app.db
litescope doctor app.db --deep # exhaustive integrity_check
litescope doctor app.db --format html -o report.htmlCombines integrity check, WAL/fragmentation health, index advisor, and schema lint in one command. Exits 1 when attention is needed — use it as a CI quality gate.
snapshot / restore — point-in-time backups
litescope snapshot app.db # consistent VACUUM INTO copy
litescope snapshot app.db --label before-migration
litescope snapshot app.db --keep 7 # retain only the 7 newest
litescope snapshot list app.db
litescope restore app.db # restore the newest snapshot
litescope restore app.db --from <snapshot.db>Snapshots live in a sibling .litescope-snapshots/ directory. Restore is
integrity-checked and takes a pre-restore safety snapshot first — the same
"did you back up?" safety net that D1 gets from Time Travel, for local and Turso.
autopilot — self-driving optimization
litescope autopilot app.db # dry-run: show the plan
litescope autopilot app.db --apply # apply the safe actions
litescope autopilot app.db --apply --aggressive
litescope autopilot --fleet litescope.fleet.yaml --applyRuns ANALYZE + PRAGMA optimize, adds missing foreign-key indexes, and
(with --aggressive) VACUUMs and drops redundant indexes — each explained in
plain language. Dry-run by default; every real change is preceded by an
automatic snapshot.
locks — diagnose "database is locked"
litescope locks app.db # static config diagnosis
litescope locks app.db --live # is a writer holding the lock now?
litescope locks app.db --watch # stream lock-state changes
litescope locks app.db --timeline # recorded contention history
litescope locks app.db --timeline --since 24hInspects journal mode, busy_timeout, locking mode, and WAL bloat, and
prescribes the exact PRAGMA/DSN fix. --live identifies the process holding
the lock right now. --watch records every observation to a local history
store; --timeline then aggregates it into a per-database contention view —
when the database was jammed, for how long, which processes held it, wait-time
percentiles, and whether the WAL checkpoint kept up.
diff — schema and data diff
litescope diff old.db new.db
litescope diff old.db new.db --format json
litescope diff local.db d1://DB_ID # local vs live D1
litescope diff local.db turso://TOKEN@ORG/prodmigrate — generate and apply migrations
litescope migrate before.db after.db --output migration.sql
litescope migrate apply prod.db migration.sql --dry-run
litescope migrate apply prod.db migration.sql --verify after.dbmigrate apply safety sequence: pre-flight integrity check → VACUUM INTO backup → single transaction → FK verification → auto-rollback on failure.
lint — schema anti-patterns
litescope lint app.db
litescope lint app.db --strict # exit 1 on info findings tooRules: no-primary-key, untyped-column, not-strict, autoincrement-overhead, non-integer-pk.
schema — inspect schema + ERD
litescope schema app.db
litescope schema app.db --erd # Mermaid ER diagramdump — portable SQL export
litescope dump app.db -o backup.sql
litescope dump app.db --schema-only
litescope dump app.db --table usersimport / export — spreadsheets and SQLite
litescope import sales.csv # → sales.db, table "sales"
litescope import budget.xlsx # first sheet → budget.db
litescope export shop.db --table orders -o orders.xlsx
litescope export shop.db --query "SELECT city, COUNT(*) FROM users GROUP BY city"Formats: CSV, TSV, JSON, Excel (.xlsx). No external dependencies.
monitor — schema drift detection
litescope monitor snapshot prod.db --output baseline.json
litescope monitor check prod.db --baseline baseline.json # exits 1 on drift
litescope monitor watch prod.db --baseline baseline.json --interval 1h --webhook https://hooks.slack.com/...serve — local web dashboard
litescope serve # opens http://127.0.0.1:7575
litescope serve --config litescope.fleet.yamlFleet topology map, health triage, schema fingerprinting, interactive ERD, a paginated data browser with a visual query builder, drag-drop import, and a visual diff panel — pick any two databases to review schema and row-count changes before applying. Entirely local, no account required.
Fleet
Manage hundreds of databases at once. Built for multi-tenant apps on Turso and D1.
# Discover all databases
litescope fleet discover turso --org my-org --token $TURSO_API_TOKEN
litescope fleet discover d1 --account $CF_ACCOUNT_ID --token $CF_API_TOKEN
# Triage the whole fleet
litescope fleet health
litescope fleet locks # roll up "database is locked" contention, worst-first
litescope fleet fingerprint # cluster by schema — find drift before it bites
# Stage a migration across the fleet
litescope fleet migrate migration.sql --dry-run
litescope fleet migrate migration.sql --canary 5
litescope fleet migrate migration.sqlCI — GitHub Action
Run Litescope on every pull request — lint the schema, diff against the base branch, and comment the blast radius so a risky migration can't merge unreviewed.
- uses: croc100/Litescope@v1
with:
args: "lint app.db --strict"
comment: "true" # post the result as a sticky PR commentargs is any Litescope command; the job exits non-zero when Litescope flags
something, failing the check. See
examples/github-actions/migration-ci.yml
for a full lint + diff workflow.
Input | Default | Description |
| — | Litescope command to run (required) |
|
| Release tag to install, or |
|
| Post output as a sticky PR comment |
|
| Directory to run in |
Install
Homebrew
brew install croc100/tap/litescopenpm / npx — for JS and wrangler users, no separate install:
npx litescope doctor app.db
npm install -g litescopeGo install
go install github.com/croc100/litescope/cmd/litescope@latestBinary download
macOS, Linux, Windows — Releases.
Remote sources
DSN | Provider |
| Local SQLite file |
| Cloudflare D1 (env: |
| Cloudflare D1 (explicit credentials) |
|
Pricing — what's free
The tool is free. We only charge to run the dashboard for you.
Free (OSS, AGPL-3.0) | Cloud (paid) | |
Every CLI command, MCP server, fleet ops | ✅ | ✅ |
| ✅ | ✅ |
Self-hosted dashboard on your own infra | ✅ | ✅ |
Hosted dashboard we run & maintain | — | ✅ |
Managed metadata ingestion, retention, alerting | — | ✅ |
Org auth, teams, SSO | — | ✅ |
Support SLA | — | ✅ |
The line is simple: the software and every feature is free and self-hostable forever. You pay only if you want us to host and operate the dashboard so you don't have to. No feature is locked behind a license key.
See litescope-site.pages.dev/pricing for the hosted plans.
License
Litescope is AGPL-3.0. Free to use, modify, and self-host. If you offer it as a network service the AGPL requires you to share your modifications. A commercial license (AGPL exception + support SLA) is available for organizations — see COMMERCIAL.md or email dl_litescope@crode.net.
Available Tools
14 toolslitescope_adviseRecommend indexesARead-onlyIdempotent
Analyze a local SQLite database for performance problems and recommend fixes: foreign keys with no index, redundant indexes, and full table scans for any supplied queries. Returns findings with runnable CREATE/DROP INDEX suggestions. Read-only — recommends, never alters the schema. (Local files only.)
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | Local SQLite file path (advise requires direct file access) | |
| queries | No | Optional SQL queries to check for full table scans |
Output Schema
| Name | Required | Description |
|---|---|---|
| path | No | The analyzed database. |
| findings | Yes | Issues with rule, severity, and a runnable suggestion. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description explicitly states 'Read-only — recommends, never alters the schema' and 'Local files only,' which adds valuable context beyond the annotations (readOnlyHint, destructiveHint). This clarifies the read-only nature and file access constraint.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the main purpose ('Analyze...'), and each sentence adds value without redundancy. It is concise and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the output schema exists (implied), the description adequately explains the inputs and behavior. It lists specific diagnostics (foreign keys, redundant indexes, table scans) but does not mention potential limitations or error cases, which is acceptable for a read-only tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema covers both parameters with descriptions (source path, optional queries). The description adds no additional meaning beyond the schema, such as formats or constraints. With 100% schema coverage, baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description starts with 'Analyze a local SQLite database for performance problems and recommend fixes' which clearly states the action and resource. It lists specific types of problems (foreign keys, redundant indexes, full table scans) and distinguishes from sibling tools like litescope_query (executes queries) and litescope_schema (shows schema).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states the tool's purpose and output (recommendations with runnable SQL), making it clear when to use it. However, it does not explicitly state when not to use it or name alternative tools, though the sibling context helps.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_autopilotSelf-driving optimize (dry-run default)A
Self-driving DBA for a local SQLite database. Derives safe maintenance and optimization actions — ANALYZE, PRAGMA optimize, missing foreign-key indexes, and (when fragmented) VACUUM / redundant-index cleanup — each explained in plain language.
Dry-run by default (apply=false): returns the plan without changing anything. apply=true executes the safe actions and requires --allow-writes; a snapshot is taken first so the run is one litescope_restore away from undo. Risky actions (VACUUM, dropping indexes) only run with aggressive=true. Local files only.
| Name | Required | Description | Default |
|---|---|---|---|
| apply | No | Execute the safe actions. Default false (dry-run). Requires --allow-writes. | |
| source | Yes | Local SQLite file path. | |
| aggressive | No | Also run risky actions (VACUUM, drop redundant indexes). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description extensively details behavioral traits beyond annotations: dry-run default, execution requiring --allow-writes, snapshot for undo, and risky actions only with aggressive=true. It also notes 'Local files only.' This adds significant context not captured by the sparse annotations (readOnlyHint=false, destructiveHint=false).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise and front-loaded with the core purpose. Every sentence adds essential information (behavior, safety, constraints) without redundancy. It is well-structured for quick comprehension.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description adequately covers the tool's functionality: what actions it derives, default mode, execution requirements, risk levels, and file restrictions. It is complete enough for an agent to decide tool selection and invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema covers all three parameters with basic descriptions. The description adds meaningful context: explains the interplay between apply and dry-run, mentions snapshot/rollback capability, and clarifies what aggressive enables (VACUUM, dropping indexes). This enhances understanding beyond schema alone.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose as 'Self-driving DBA for a local SQLite database' that derives safe maintenance and optimization actions like ANALYZE, PRAGMA optimize, and missing foreign-key indexes. It distinguishes from sibling tools (e.g., litescope_advise, litescope_check) by emphasizing automated derivation and execution of optimization actions.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains the default dry-run behavior and how to enable execution (apply=true, aggressive=true for risky actions), but does not explicitly state when to use this tool versus its siblings or when not to use it. No direct comparison or exclusion criteria are provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_checkVerify backup integrityARead-onlyIdempotent
Verify a SQLite backup. Runs a PRAGMA integrity check; if 'against' is given, also compares schema and row counts to a reference database. Returns a JSON report. Read-only. (Local files only.)
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | Also compare row counts per table | |
| source | Yes | Local path to the backup database to verify | |
| against | No | Optional local reference database to compare schema against |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses key behaviors: runs PRAGMA integrity check, compares schema/row counts when 'against' is given, returns JSON report, and notes read-only and local-file constraints. These details add value beyond the annotations, which already indicate read-only and idempotent hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise (two sentences) yet packs all essential information. It front-loads the primary action ('Verify a SQLite backup') and efficiently communicates the conditional behavior and constraints.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has three well-documented parameters in the schema, rich annotations, and no output schema, the description is complete. It explains the core logic (integrity check) and the optional comparison, which suffices for correct usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With 100% schema coverage, the description adds extra semantics by explaining that 'against' triggers schema and row count comparison, beyond the schema's 'Optional local reference database to compare schema against'. This clarifies the tool's behavior beyond the parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: verifying a SQLite backup via PRAGMA integrity check, with optional comparison against a reference database. It distinguishes itself from sibling tools like litescope_diff by focusing on backup verification specifically.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implicitly guides usage by stating 'Read-only. (Local files only.)' and describing the optional 'against' parameter. While it doesn't explicitly list alternatives, the context of backup verification is clear enough for an agent to decide when to invoke this tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_d1_listList D1 databasesARead-onlyIdempotent
List all Cloudflare D1 databases in the account. Returns each database's UUID, name, creation date, table count, and the DSN to use with other litescope tools. Requires CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID environment variables. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| count | Yes | Number of databases. |
| databases | Yes | Each D1 database with uuid, name, table count, and dsn. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and destructiveHint false, so the description adds value by specifying the exact return fields (UUID, name, creation date, table count, DSN) and the required environment variables. This is helpful context beyond what annotations provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no wasted words. The first sentence states the purpose immediately, and the second adds return values and prerequisites. It is optimally sized for an agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has no parameters and an output schema exists, the description covers all necessary information: purpose, return values, and required environment variables. It is fully sufficient for an AI agent to select and invoke the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are no parameters, so the description cannot add parameter details. The baseline for zero parameters is 4, and the description does not need to elaborate further.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the action ('List') and the resource ('all Cloudflare D1 databases in the account'). It is specific and distinguishes it from sibling tools, which include other litescope commands but no other list tool for D1 databases.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly indicates when to use (to list databases) and mentions required environment variables, but it does not provide explicit guidance on when not to use or mention alternatives among siblings. The context is clear but lacks exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_diffDiff two databasesARead-onlyIdempotent
Compare two SQLite or D1 databases and return their schema and row-count differences as JSON. Works across any combination of local files, D1, and Turso — e.g. diff a local migration target against a live D1 database. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| new | Yes | Changed ('after') source — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). | |
| old | Yes | Baseline ('before') source — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
Output Schema
| Name | Required | Description |
|---|---|---|
| summary | Yes | Counts of tables added/removed/modified. |
| data_changes | No | Per-table row-count differences (present when data differs). |
| schema_changes | Yes | Per-table schema differences. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, destructiveHint=false, and idempotentHint=true, so the safety profile is clear. The description adds value by specifying the output format (JSON) and supported database sources, which are not covered by annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: first sentence states purpose and output, second sentence expands on sources and gives an example. No wasted words; each sentence provides essential information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the presence of an output schema (covering return values), detailed parameter descriptions (100% coverage), and annotations that cover safety and idempotency, the description is complete. It adequately informs an AI agent about the tool's functionality and usage scope.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and both parameters have detailed descriptions already. The tool description adds context by defining 'old' as baseline and 'new' as changed, and gives examples of sources and authentication notes, which enhances understanding beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool compares two databases and returns schema and row-count differences as JSON, which is a specific verb+resource. It distinguishes from sibling litescope_migrate_diff by specifying the output is schema and row-count differences, not just migration-related.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context on when to use the tool (e.g., diff a local migration target against a live D1 database) and lists supported database types (local files, D1, Turso). However, it does not explicitly state when not to use or mention alternatives among sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_fingerprintFingerprint fleet schemasARead-onlyIdempotent
Cluster a fleet of SQLite databases by schema and report how many distinct schemas are running, with each cluster's drift from the canonical (largest) one. Reads a fleet config file (litescope.fleet.yaml). Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| tag | No | Only include databases with this tag | |
| config | No | Path to the fleet config (default: litescope.fleet.yaml) |
Output Schema
| Name | Required | Description |
|---|---|---|
| total | No | Databases successfully fingerprinted. |
| clusters | Yes | Schema clusters, canonical first, with drift from canonical. |
| unreachable | No | Databases that could not be read. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already provide readOnlyHint, idempotentHint, destructiveHint. Description adds behavioral context: reads a fleet config file (litescope.fleet.yaml), outputs clusters with drift from canonical. Does not contradict annotations. Good additional context beyond structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise, front-loaded sentences. Each sentence adds value: first explains core function, second mentions config file and read-only nature. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Tool has output schema (so return format is covered), schema coverage 100%, annotations complete. Description provides all necessary context: what it does, what it reads, and its read-only nature. Fully adequate for agent usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters ('tag', 'config') are already described in the schema. Description does not add extra meaning or usage details for parameters, meeting baseline expectation for high coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool clusters SQLite databases by schema and reports distinct schemas and drift from canonical. Verb 'cluster and report' is specific, resource is 'fleet of SQLite databases', outcome is well-defined. Distinguishes from siblings like litescope_diff or litescope_schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Description indicates it reads a fleet config file and is read-only, implying usage for fleet-level schema analysis. No explicit guidance on when to use versus alternatives or when not to use. Adequate but lacks exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_fleet_healthFleet health overviewARead-onlyIdempotent
Triage operational faults across a whole fleet of SQLite databases in parallel — corruption, WAL bloat, fragmentation, reachability — sorted worst-first. Reads a fleet config file (litescope.fleet.yaml). Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| tag | No | Only include databases with this tag | |
| deep | No | Use the exhaustive integrity_check instead of quick_check | |
| config | No | Path to the fleet config (default: litescope.fleet.yaml) |
Output Schema
| Name | Required | Description |
|---|---|---|
| results | Yes | Per-database health reports, worst-first. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false. The description adds meaningful behavioral context: operations are performed in parallel across the fleet, results are sorted worst-first, and it relies on a fleet config file. The explicit 'Read-only' statement reinforces the annotations. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise: two sentences covering purpose, scope, specifics, and read-only nature. Every word adds value; no filler or repetition. It is front-loaded with the primary action and key differentiators.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (fleet, parallel, multiple fault types) and the presence of a full output schema, the description provides sufficient context. It explains the parallel triage, fault types, sorting, and config file dependency. The only minor gap is no mention of the output format, but the output schema covers that. Overall, complete for the task.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% (all three parameters have descriptions in the input schema). The description does not add additional semantics beyond what the schema provides (e.g., tag, deep, config). According to guidelines, when coverage is high, baseline is 3, and no extra information is provided here.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: triaging operational faults across a fleet of SQLite databases in parallel, listing specific fault types (corruption, WAL bloat, fragmentation, reachability) and sorting worst-first. This verb+resource combination ('triage operational faults across a fleet') distinguishes it from sibling tools like litescope_health, which likely targets single databases.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for fleet-wide health triage and explicitly marks the tool as read-only, but it does not provide explicit guidance on when to use this tool versus alternatives (e.g., litescope_health for single databases, litescope_check for specific checks). The usage context is implied but not fully delineated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_healthInspect database healthARead-onlyIdempotent
Inspect a SQLite or D1 database for operational faults: corruption (PRAGMA integrity check), WAL bloat from a starved checkpoint, freelist fragmentation, and reachability. Returns a JSON report with a severity (ok / warning / critical) and a list of issues. Read-only.
For D1: set CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID and use source=d1://DB_ID.
| Name | Required | Description | Default |
|---|---|---|---|
| deep | No | Use the exhaustive integrity_check instead of the faster quick_check | |
| source | Yes | Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
Output Schema
| Name | Required | Description |
|---|---|---|
| issues | No | Detected problems (empty when healthy). |
| severity | Yes | Overall verdict. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false. The description adds valuable behavioral context: lists specific integrity checks, output format (JSON with severity and issues), and environment variable requirements for D1. This goes beyond what annotations provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two paragraphs with no wasted words. The first paragraph covers purpose and output; the second covers D1 setup. It is efficient, though the D1 instruction could be integrated into the parameter description for better structure.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, the description does not need to detail return values. It covers the core purpose, specific checks, and important usage notes (environment variables, source format). Missing is guidance on error handling or performance, but it is fairly complete for a health inspection tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the description does not need to add parameter details. It mentions source examples (d1://DB_ID) but does not clarify the 'deep' boolean or format requirements beyond the schema. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it inspects SQLite/D1 database health for specific faults (corruption, WAL bloat, freelist fragmentation, reachability). The verb 'inspect' and resource 'database health' are specific, and the listed checks distinguish it from sibling tools like litescope_locks or litescope_fleet_health.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description notes it is read-only and provides setup instructions for D1 sources. However, it does not explicitly state when to use this tool versus alternatives or when not to use it (e.g., for non-health queries). The context is clear but lacks exclusion guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_locksDiagnose database locksARead-onlyIdempotent
Diagnose "database is locked" / SQLITE_BUSY and writer-starvation problems — the most common SQLite production failure. Inspects journal mode, busy_timeout, locking mode, and WAL bloat for local files, and returns provider-specific guidance for D1 and Turso. Each finding includes the exact PRAGMA or DSN change to apply. Returns a JSON report with a verdict (ok / attention / critical).
Set live=true (local files only) to instead probe the current lock state: whether a writer is holding the lock right now and which processes have the file open. Use this when an app is actively reporting "database is locked". Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| live | No | Probe the live lock state right now instead of static PRAGMA config (local files only) | |
| source | Yes | Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate read-only, idempotent, non-destructive. The description adds significant behavioral context: it explains the two modes (static vs live), the provider-specific guidance, and explicitly states it's read-only. It also notes that live mode only works for local files. No contradictions with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise yet packed with essential information. It is well-structured: first paragraph covers the primary purpose and output, second paragraph the live mode. Every sentence adds value, and the information is front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description adequately describes the return format (JSON verdict). It covers both modes, all parameters, limitations, and provider specifics. It is complete enough for an agent to use effectively without guessing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description goes well beyond: for 'source', it gives concrete examples and environment variable requirements for D1 and Turso; for 'live', it clarifies its purpose and the local-files-only limitation. This adds substantial meaning that the schema alone does not convey.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it diagnoses 'database is locked' errors and writer-starvation problems, inspects specific SQLite parameters (journal mode, busy_timeout, etc.), and returns a JSON report. It distinguishes between static config check and live lock probing, and its purpose is distinct from sibling tools like litescope_health or litescope_query.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly tells when to use the tool (for 'database is locked' SQLITE_BUSY or writer-starvation) and when to use the live flag (when actively reporting locked). It also notes that live mode is for local files only. However, it does not explicitly contrast with sibling tools, though the context implies this is the go-to for lock diagnostics.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_migrate_diffGenerate migration SQLARead-onlyIdempotent
Diff two SQLite or D1 databases and return the migration SQL that would bring the 'old' source up to the 'new' schema — without applying it or computing blast-radius. Useful when you only need the SQL to review or pass to litescope_migrate_apply. For a full blast-radius analysis use litescope_migrate_plan. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| new | Yes | Target ('after') source with the desired schema — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). | |
| old | Yes | Current ('before') source — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint. The description adds non-obvious behaviors: it does not apply the migration and does not compute blast radius. It also explicitly says 'Read-only'. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences plus 'Read-only' suffix, no fluff. First sentence states purpose, second sentence gives use case and alternative. Extremely efficient and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with two parameters and comprehensive schema descriptions, the description is mostly complete. It doesn't describe the output format (SQL text), but given no output schema, this is acceptable. The sibling references add context. Minor gap: environment variable dependencies mentioned only in schema, but overall sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline is 3. The description does not add additional parameter meaning beyond what the schema already provides, such as the detailed DSN formats. It is adequate but not extra.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool diffs two databases and returns migration SQL without applying or computing blast radius. It distinguishes from siblings like litescope_migrate_plan and litescope_migrate_apply, using specific verb 'diff' and resource 'SQLite or D1 databases'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicit when to use: 'when you only need the SQL to review or pass to litescope_migrate_apply'. Explicit alternative: 'For a full blast-radius analysis use litescope_migrate_plan'. This provides clear guidance for agent decision-making.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_migrate_planPlan a migration (no apply)ARead-onlyIdempotent
Plan a migration between two SQLite or D1 databases WITHOUT applying it. Returns the migration SQL plus a blast-radius analysis: each operation classified safe / risky / destructive, with an estimated write-lock duration for table rebuilds. Use this before applying any migration to a D1 database. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| new | Yes | Target ('after') source with the desired schema — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). | |
| old | Yes | Current ('before') source — Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
Output Schema
| Name | Required | Description |
|---|---|---|
| sql | Yes | The migration SQL. |
| operations | Yes | Each operation classified safe/risky/destructive with lock estimate. |
| statements | Yes | Number of SQL statements in the plan. |
| destructive | Yes | True if any operation drops or rewrites data. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds significant behavioral context beyond annotations: returns SQL and blast-radius with safety classification and lock duration estimates, and reaffirms read-only nature. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loading the core purpose and output. Every sentence adds value: purpose, output details, usage guidance, and safety reaffirmation. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the annotations cover safety and idempotency, and an output schema exists for return values, the description is complete. It covers what the tool returns, when to use it, and that it's read-only, leaving no critical gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents both 'old' and 'new' parameters thoroughly. The description adds no additional detail beyond stating the parameters exist, meeting the baseline for this dimension.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool plans a migration without applying it, returning SQL and blast-radius analysis. This distinguishes it from potential apply-like siblings and explicitly mentions 'read-only'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says 'Use this before applying any migration to a D1 database,' providing clear context. It lacks explicit when-not-to-use or alternatives, but the context is strong enough for selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_queryRun a read-only queryARead-onlyIdempotent
Run a read-only SQL query on any SQLite or D1 database and return the results as JSON. Only SELECT statements and read-only PRAGMAs are allowed. This is the primary tool for an AI agent to explore data in a D1 database.
Token budgeting: results are capped at max_rows (default 200) so a large table won't blow your context window — the response reports total_rows and truncated. Use the columns argument to project only the fields you need. Narrow with LIMIT / WHERE for precise reads.
For D1: set CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID and use source=d1://DB_ID.
| Name | Required | Description | Default |
|---|---|---|---|
| sql | Yes | A read-only SQL query (SELECT or read-only PRAGMA). Mutations are rejected. | |
| source | Yes | Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). | |
| columns | No | Optional: keep only these columns in each row (projection) to save context. | |
| max_rows | No | Maximum rows to return (default 200, max 2000). Excess rows are dropped and reported via truncated. |
Output Schema
| Name | Required | Description |
|---|---|---|
| rows | Yes | The result rows. |
| count | Yes | Rows returned after truncation. |
| truncated | Yes | True when total_rows exceeded max_rows. |
| total_rows | Yes | Rows the query produced before truncation. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate readOnlyHint, idempotentHint, and destructiveHint. The description adds useful behavioral details beyond annotations: results are capped at max_rows (default 200, max 2000), the response reports total_rows and truncated, and mutations are rejected. This provides context for AI agents.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise and well-structured. The first sentence immediately states the purpose, followed by clear paragraphs on constraints, token budgeting, and setup. Every sentence adds value without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity (4 parameters, output schema exists), the description is complete. It covers all aspects needed for correct invocation: query restrictions, row limits, projection, source configuration, and default behavior. No gaps are apparent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline is 3. The description adds meaningful context: explains the default and max for max_rows, the projection benefit of columns, and clarifies source format with examples (local, D1, Turso). This goes beyond the schema's descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it runs a read-only SQL query on SQLite or D1 databases returning JSON. It specifies only SELECT and read-only PRAGMAs are allowed, distinguishing it from sibling tools like litescope_schema or litescope_health by being the primary data exploration tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context on when to use the tool (exploring data) and gives practical guidance on token budgeting, row limits, column projection, and narrowing queries. However, it does not explicitly exclude scenarios or mention alternative sibling tools for different tasks.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_schemaInspect schemaARead-onlyIdempotent
Load the schema of a SQLite or D1 database — tables, columns (name, type, not-null, primary key), and indexes. Returns JSON. Read-only.
Works with local files, D1, and Turso. For D1: set CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID and use source=d1://DB_ID.
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | Database source: a local file path (./app.db), a Cloudflare D1 DSN (d1://DB_ID when CLOUDFLARE_API_TOKEN+CLOUDFLARE_ACCOUNT_ID are set, or d1://TOKEN@ACCOUNT_ID/DB_ID), or a Turso DSN (turso://TOKEN@ORG/DB). |
Output Schema
| Name | Required | Description |
|---|---|---|
| tables | Yes | Tables with their columns and indexes. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, and non-destructive hints. The description adds that it returns JSON and requires environment variables for D1, providing useful behavioral context beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences with no wasted words. The first sentence captures the core purpose, followed by supported sources and setup notes. Front-loaded and efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with one parameter and an output schema, the description fully covers what it does, what it returns, and prerequisites. No gaps given the simplicity and existing structured fields.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema covers the single parameter completely. The description adds examples of source formats (e.g., ./app.db, d1://DB_ID) and clarifies the DSN patterns, providing additional meaning beyond the schema description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it loads the schema of SQLite/D1 databases, listing tables, columns, and indexes, and returns JSON. It is distinct from sibling tools like litescope_query or litescope_check, which focus on querying or health checks.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains the tool works with local files, D1, and Turso, and provides setup instructions for D1 (env vars). It lacks explicit exclusions but gives clear context for when to use.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
litescope_snapshot_listList snapshotsARead-onlyIdempotent
List point-in-time snapshots (local backups) for a local SQLite database, newest first. Snapshots are created with litescope_snapshot (requires --allow-writes). Use this to find a snapshot to restore, or to confirm a database has a backup before a risky write. Read-only; local files only.
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | Local SQLite file path. |
Output Schema
| Name | Required | Description |
|---|---|---|
| count | Yes | Number of snapshots. |
| source | Yes | The database the snapshots belong to. |
| snapshots | Yes | Snapshots, newest first, with path, label, and timestamp. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, destructiveHint=false, and idempotentHint=true. The description adds behavioral details beyond these: 'newest first', 'local files only', and that snapshots are created with litescope_snapshot requiring --allow-writes. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences and a short phrase, front-loaded with the action and result. Every sentence adds value: first states function and ordering, second provides usage guidance and constraint. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, known output schema), the description covers purpose, usage, constraints, and behavioral traits. With output schema present, explanation of return values is not needed. It is complete for an agent to select and invoke correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with one parameter 'source' described as 'Local SQLite file path.' The description reinforces this by mentioning 'local SQLite database' and 'local files only' but does not add new semantic details beyond the schema. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'list', the resource 'point-in-time snapshots (local backups)', and the scope 'for a local SQLite database, newest first'. It distinguishes from sibling tools by focusing on snapshots, which are unique among the listed siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage context: 'Use this to find a snapshot to restore, or to confirm a database has a backup before a risky write.' It also mentions the creation tool (litescope_snapshot) and the requirement for --allow-writes, guiding when to use this tool vs. alternatives. It also states 'Read-only; local files only'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.9.0- Added
litescope_autopilot - Added
litescope_health - Added
litescope_locks - Added
litescope_migrate_plan - Added
litescope_schema - Added
litescope_snapshot_list
6 tool updates
v0.8.0- Removed
litescope_autopilot - Removed
litescope_health - Removed
litescope_locks - Removed
litescope_migrate_plan - Removed
litescope_schema - Removed
litescope_snapshot_list
14 tool updates
v0.6.4- First observed
litescope_advise - First observed
litescope_autopilot - First observed
litescope_check - First observed
litescope_d1_list - First observed
litescope_diff - First observed
litescope_fingerprint - First observed
litescope_fleet_health - First observed
litescope_health - First observed
litescope_locks - First observed
litescope_migrate_diff - First observed
litescope_migrate_plan - First observed
litescope_query - First observed
litescope_schema - First observed
litescope_snapshot_list
TDQS
Scored across 14 tools
Most tools target clearly distinct concerns (health, locks, advise, schema, query, diff, migrate_plan vs migrate_diff), and descriptions explicitly disambiguate near-neighbors like migrate_plan vs migrate_diff. However, the diagnostics cluster (health, fleet_health, locks, advise) shares substantial conceptual overlap, and the distinction between single-db health and advise requires reading the descriptions carefully.
All tools share a consistent litescope_ prefix and snake_case convention, with several clear verb_noun names (migrate_plan, snapshot_list, d1_list, fleet_health). A few names are bare nouns/verbs (health, schema, locks, advise, query, diff, fingerprint), which is readable but slightly less predictable than a uniform verb_noun pattern.
14 tools is well within a healthy range and each covers a distinct facet of the SQLite/D1 lifecycle: diagnostics, schema exploration, migration planning, fleet analysis, snapshots, and backup verification. No tool appears redundant or filler.
The read-only diagnostic surface is broad and coherent, but the toolset has dead ends: litescope_migrate_diff references a litescope_migrate_apply that is absent, and descriptions mention litescope_snapshot (create) and litescope_restore which are not in the set. An agent can plan migrations and inspect snapshots but cannot apply migrations or create/restore backups, which will cause workflow failures.
Maintenance
Related MCP Connectors
- dataOAuthco.thinair
PostgreSQL, MySQL, and SQL Server in one session. 26 read-only MCP tools for AI agents.
Explore, query, and inspect SQLite databases with ease. List tables, preview results, and view det…
- WoWSQLOAuthcom.wowsql
Managed Postgres MCP: projects, SQL, docs search, and storage buckets via OAuth.
Query, join, profile, clean and convert CSV/JSON/Parquet with server-side DuckDB over MCP.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA universal SQLite database management tool that enables SQL query execution through MCP protocol. Supports SELECT/INSERT/UPDATE/DELETE/CREATE operations with built-in SQL injection protection across stdio, SSE, and streamable-http communication modes.MIT
- AlicenseNot gradedqualityCmaintenanceExposes sqlite3 database functionality as MCP tools, enabling SQL query execution, schema management, and CRUD operations.1MIT
- AlicenseNot gradedqualityCmaintenanceRead-only SQLite access for AI agents in a single ~1 MB static binary. Query tool with row limits, list_tables, and table schemas exposed as MCP resources. The database is opened read-only, so writes fail at the SQLite layer. No Python, no Node, no runtime to install; SQLite is compiled in. Binaries for Linux, macOS, and Windows.MIT
- AlicenseNot gradedqualityDmaintenanceProvides a set of MCP tools to let AI assistants like Claude, Cursor, and VS Code Copilot interact with SQLite databases, supporting querying, schema management, and data import/export.17 npmMIT