Skip to main content
Glama
raphaeljordao86

guarded-postgres-mcp

execute

Destructive

Runs one guarded SQL DML/DDL statement in its own transaction, blocking unsafe writes and requiring confirmation for large or catch-all changes before commit and audit logging.

Instructions

Runs ONE DML/DDL statement (UPDATE, INSERT, DELETE, ALTER, CREATE) in its own transaction, behind guardrails. Blocked: DELETE/UPDATE without their own WHERE (anywhere in the statement), TRUNCATE, DROP (except snapshot tables), ALTER ... DROP COLUMN, DO/CALL, BEGIN/COMMIT, SET and EXPLAIN. Requires i_understand=true when the statement changes more than GUARD_MAX_ROWS rows (default 1000), has a WHERE made only of constants (e.g. WHERE 1=1), or hides DML inside a WITH. Rolled back if it leaves a sequence behind MAX of its key. Commits only when every check passes, and writes an audit log entry.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sqlYesOne SQL statement (no BEGIN/COMMIT)
descriptionYesShort description of what the statement does (stored in the audit log)
i_understandNoBoolean true confirms a large or catch-all operation. Strings are rejected.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.1.0

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Far exceeds the annotations: annotations only declare destructive/not-read-only, while the description discloses transaction scoping, the guardrail set, rollback conditions ('leaves a sequence behind MAX of its key'), the commit condition, and the audit-log side effect. All the risk behavior an agent needs before issuing a mutation is stated.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four dense sentences, front-loaded with the core action and scope before the constraints; nearly every clause carries actionable content. It is on the long side and the blocked/required lists are packed into run-on clauses, but nothing is padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with no output schema, the description covers the important outcome behavior (atomic commit vs rollback, audit entry) and all failure triggers. It stops short of describing the success response shape, which is the only notable gap for an agent deciding how to interpret the result.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description adds real meaning: it defines when i_understand becomes mandatory (over GUARD_MAX_ROWS=1000, constant-only WHERE, WITH-hidden DML) and reiterates the no-BEGIN/COMMIT constraint on sql. Only the audit-log semantics of description are repeated rather than extended.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Runs ONE DML/DDL statement') and pins the scope with 'in its own transaction, behind guardrails,' which is exactly what separates it from execute_transaction and the read-only query sibling. The enumerated statement types (UPDATE, INSERT, DELETE, ALTER, CREATE) leave no ambiguity about what it accepts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides unusually strong negative guidance — an explicit blocked-statement list and the conditions that force i_understand=true — which tells the agent when the call will fail. It does not explicitly route to siblings (e.g. 'use query for SELECTs, execute_transaction for multiple statements'), so the positive when-to-use is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools