Skip to main content
Glama
turbot
by turbot

Steampipe 模型上下文协议 (MCP) 服务器

使用Steampipe解锁 AI 驱动的基础设施分析能力!这款模型上下文协议服务器可将 Claude 等 AI 助手无缝连接到您的云基础设施数据,从而实现对您整个云资产的自然语言探索和分析。

Steampipe MCP 连接 AI 助手和您的基础设施数据,允许自然语言:

  • 跨 AWS、Azure、GCP 和 100 多种云服务的查询

  • 安全性和合规性分析

  • 成本和资源优化

  • 查询开发援助

可与本地Steampipe安装和Turbot Pipes工作区配合使用,提供对所有云和 SaaS 数据的安全、只读访问。

安装

先决条件

  • Node.js v16 或更高版本(包括npx

  • 供本地使用: Steampipe安装并运行( steampipe service start

  • 对于 Turbot Pipes: Turbot Pipes工作区和连接字符串

配置

将 Steampipe MCP 添加到您的 AI 助手的配置文件中:

{
  "mcpServers": {
    "steampipe": {
      "command": "npx",
      "args": [
        "-y",
        "@turbot/steampipe-mcp"
      ]
    }
  }
}

默认情况下,这将连接到您本地的 Steampipe 安装,地址为postgresql://steampipe@localhost:9193/steampipe 。请确保先运行steampipe service start

要连接到Turbot Pipes工作区,请将连接字符串添加到参数:

{
  "mcpServers": {
    "steampipe": {
      "command": "npx",
      "args": [
        "-y",
        "@turbot/steampipe-mcp",
        "postgresql://my_name:my_pw@workspace-name.usea1.db.pipes.turbot.com:9193/abc123"
      ]
    }
  }
}

AI助手设置

助手

配置文件位置

设置指南

克劳德桌面

claude_desktop_config.json

Claude Desktop MCP 指南 →

光标

~/.cursor/mcp.json

光标 MCP 指南 →

保存配置文件并重新启动 AI 助手以使更改生效。

Related MCP server: tailpipe-mcp

提示指南

首先,运行 MCP 服务器自带的best_practices提示符,教你的法学硕士如何最好地使用 Steampipe。然后,你可以问任何问题!

探索您的云基础设施:

What AWS accounts can you see?

简单、具体的问题很有效:

Show me all S3 buckets that were created in the last week

生成基础设施报告:

List my EC2 instances with their attached EBS volumes

深入安全分析:

Find any IAM users with access keys that haven't been rotated in the last 90 days

获取合规性见解:

Show me all EC2 instances that don't comply with our tagging standards

探索潜在风险:

Analyze my S3 buckets for security risks including public access, logging, and encryption

请记住:

  • 具体说明您想要分析哪些云资源(EC2、S3、IAM 等)

  • 如果您对特定地区或帐户感兴趣,请提及

  • 在添加复杂条件之前先从简单查询开始

  • 使用自然语言 - LLM 将处理 SQL 翻译

  • 大胆探索——法学硕士可以帮助您发现整个基础设施的见解!

功能

工具

  • steampipe_query

    • 使用 SQL 查询云和安全日志。

    • 为了获得最佳性能:使用 CTE 而不是连接,限制请求的列。

    • 所有查询都是只读的并使用 PostgreSQL 语法。

    • 输入: sql (字符串):使用 PostgreSQL 语法执行的 SQL 查询

  • steampipe_table_list

    • 列出所有可用的 Steampipe 表。

    • 可选输入: schema (字符串):按特定模式过滤表

    • 可选输入: filter (字符串):按 ILIKE 模式过滤表(例如“%ec2%”)

  • steampipe_table_show

    • 获取有关特定表的详细信息,包括列定义、数据类型和描述。

    • 输入: name (字符串):显示详细信息的表的名称(可以是模式限定的,例如“aws_account”或“aws.aws_account”)

    • 可选输入: schema (字符串):包含表的模式

  • steampipe_plugin_list

    • 列出系统上安装的所有 Steampipe 插件。插件提供对不同数据源的访问,例如 AWS、GCP 或 Azure。

    • 无需输入参数

  • steampipe_plugin_show

    • 获取特定 Steampipe 插件安装的详细信息,包括版本、内存限制和配置。

    • 输入: name (字符串):显示详细信息的插件名称

提示

  • 最佳实践

    • 使用 Steampipe 数据的最佳实践

    • 提供以下方面的详细指导:

      • 响应样式和格式约定

      • 使用 CTE(WITH 子句)与连接

      • SQL 语法和样式约定

      • 色谱柱选择与优化

      • 模式探索和理解

      • 查询结构和组织

      • 性能考虑和缓存

      • 错误处理和故障排除

资源

  • 地位

    • 表示 Steampipe 连接的当前状态

    • 属性包括:

      • connection_string:当前数据库连接字符串

      • 状态:连接状态(已连接/已断开连接)

该资源使 AI 工具能够检查和验证与 Steampipe 实例的连接状态。

发展

克隆和设置

  1. 克隆存储库并导航到目录:

git clone https://github.com/turbot/steampipe-mcp.git
cd steampipe-mcp
  1. 安装依赖项:

npm install
  1. 构建项目:

npm run build

测试

如需使用支持 MCP 的 AI 工具测试本地开发版本,请更新 MCP 配置以使用本地dist/index.js包(而非 npm 包)。例如:

{
  "mcpServers": {
    "steampipe": {
      "command": "node",
      "args": [
        "/absolute/path/to/steampipe-mcp/dist/index.js",
        "postgresql://steampipe@localhost:9193/steampipe"
      ]
    }
  }
}

或者,使用 MCP 检查器来验证服务器实现:

npx @modelcontextprotocol/inspector dist/index.js

环境变量

以下环境变量可用于配置 MCP 服务器:

  • STEAMPIPE_MCP_LOG_LEVEL :控制服务器日志记录详细程度(默认值: info

  • STEAMPIPE_MCP_WORKSPACE_DATABASE :覆盖默认的 Steampipe 连接字符串(默认值: postgresql://steampipe@localhost:9193/steampipe

开源与贡献

此仓库基于Apache 2.0 许可证发布。请参阅我们的行为准则。我们期待与您合作!

SteampipeTurbot HQ, Inc.独家基于此开源软件开发的产品。该产品根据我们的商业条款进行分发。其他方可以自行分发该软件,但不得使用 Turbot 的任何商标、云服务等。您可以访问我们的开源常见问题解答了解更多信息。

介入

在 Slack 上加入 #steampipe →

想帮忙却不知从何下手?那就从以下help wanted中选择一张吧:

Available Tools

5 tools
steampipe_plugin_listA

List all Steampipe plugins installed on the system. Plugins provide access to different data sources like AWS, GCP, or Azure.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It describes what the tool does (lists plugins) and provides useful context about plugins providing access to data sources, but doesn't disclose behavioral traits like whether this requires specific permissions, how results are formatted, or if there are any rate limits. It adds some value but lacks operational details.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences with zero waste. First sentence states the core purpose, second adds helpful context about plugins. Well-structured and front-loaded with the essential information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no annotations, no output schema, and moderate complexity (listing operation), the description is adequate but incomplete. It explains what the tool does and provides context about plugins, but lacks details about return format, error conditions, or operational constraints that would be helpful for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has 0 parameters with 100% schema description coverage, so no parameter documentation is needed. The description appropriately doesn't discuss parameters, maintaining focus on the tool's purpose. Baseline for 0 parameters is 4, as it avoids unnecessary parameter discussion.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the specific action ('List all') and resource ('Steampipe plugins installed on the system'), with additional context about what plugins provide. It distinguishes from siblings like steampipe_plugin_show (detail view) and steampipe_table_list (different resource type).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage when needing to see installed plugins, but doesn't explicitly state when to use this vs. alternatives like steampipe_plugin_show for detailed plugin information or steampipe_table_list for table listings. No explicit exclusions or prerequisites are mentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

steampipe_plugin_showA

Get details for a specific Steampipe plugin installation, including version, memory limits, and configuration.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesName of the plugin to show details for

TDQS

A3.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions what details are returned (version, memory limits, configuration) but does not cover other important aspects such as error handling (e.g., what happens if the plugin doesn't exist), permissions required, or whether it's a read-only operation. This leaves significant gaps for a tool with no annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, well-structured sentence that efficiently conveys the tool's purpose and key details. It is front-loaded with the main action and resource, and every part of the sentence adds value without redundancy or unnecessary information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (simple read operation with one parameter) and the lack of annotations and output schema, the description is moderately complete. It specifies what details are retrieved, but it does not fully compensate for the missing behavioral context (e.g., error handling, permissions) or describe the return format, which would be needed for higher completeness in the absence of an output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema description coverage is 100%, with the parameter 'name' clearly documented in the schema as 'Name of the plugin to show details for.' The description does not add any additional meaning or context beyond what the schema provides, such as format examples or constraints. With high schema coverage, the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the specific action ('Get details') and resource ('a specific Steampipe plugin installation'), distinguishing it from siblings like 'steampipe_plugin_list' (which lists all plugins) and 'steampipe_table_show' (which shows table details). It explicitly mentions what details are included: version, memory limits, and configuration.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage context by specifying 'a specific Steampipe plugin installation,' suggesting it should be used when details for a particular plugin are needed. However, it does not explicitly state when not to use it or name alternatives like 'steampipe_plugin_list' for listing all plugins, which would be required for a score of 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

steampipe_queryA

Query cloud infrastructure, SaaS, APIs, code and more with SQL.

Queries are read-only and must use PostgreSQL syntax.

For best performance: limit columns requested, use materialized CTEs instead of joins. Trust the search path unless sure you need to specify a schema.

Check available tables and columns before querying using steampipe_table_list and steampipe_table_show.

ParametersJSON Schema
NameRequiredDescriptionDefault
sqlYesThe SQL query to execute. Must use PostgreSQL syntax and be read-only.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key traits: queries are 'read-only,' must use 'PostgreSQL syntax,' and includes performance tips (limit columns, use CTEs, trust search path). This covers safety, syntax, and optimization, though it lacks details on error handling or output format.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured and front-loaded, starting with the core purpose. Each sentence adds value: purpose, constraints, performance tips, and sibling tool references. There is no wasted text, making it efficient and easy to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (querying multiple data sources) and lack of annotations/output schema, the description does a good job covering key aspects: purpose, constraints, performance, and sibling tool integration. However, it doesn't explain return values or error cases, leaving some gaps for a tool with no output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema description coverage is 100%, with the parameter 'sql' fully documented in the schema. The description adds minimal semantics beyond this, only reiterating that SQL must be 'read-only' and use 'PostgreSQL syntax,' which is already in the schema. This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Query cloud infrastructure, SaaS, APIs, code and more with SQL.' It specifies the verb ('query') and resources, but doesn't explicitly differentiate from sibling tools like steampipe_table_list/show, which are mentioned for checking tables rather than querying. This makes it clear but not fully sibling-distinguished.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit guidance on when to use this tool vs alternatives: it instructs to 'Check available tables and columns before querying using steampipe_table_list and steampipe_table_show.' This clearly defines a usage sequence and distinguishes it from sibling tools, offering practical alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

steampipe_table_listB

List all available Steampipe tables. Use schema and filter parameters to narrow down results.

ParametersJSON Schema
NameRequiredDescriptionDefault
schemaNoOptional schema name to filter tables by. If not provided, lists tables from all schemas.
filterNoOptional filter pattern to match against table names. Use ILIKE syntax, including % as a wildcard.

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions that the tool 'lists' tables, which implies a read-only operation, but doesn't specify whether this requires authentication, how results are returned (e.g., pagination, format), or any rate limits. The description adds minimal behavioral context beyond the basic action.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise with just two sentences that are front-loaded and waste-free. The first sentence states the core purpose, and the second adds essential usage guidance, making every word earn its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's low complexity (2 optional parameters, no output schema, no annotations), the description is minimally adequate. It covers the basic purpose and hints at parameter usage but lacks details on behavioral aspects like authentication, result format, or error handling, which would be helpful for an agent to use it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The description mentions that 'schema and filter parameters' can be used to 'narrow down results,' which adds some context about their purpose. However, with 100% schema description coverage, the input schema already fully documents both parameters, including their types, optionality, and usage details (e.g., ILIKE syntax for filter). The description provides only marginal value beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('List all available Steampipe tables') and the resource ('Steampipe tables'), making the purpose immediately understandable. However, it doesn't explicitly differentiate this tool from its sibling 'steampipe_table_show' which likely shows details of a specific table rather than listing all tables.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides implied usage guidance by mentioning that schema and filter parameters can be used to 'narrow down results,' suggesting this tool is for listing tables with optional filtering. However, it doesn't explicitly state when to use this tool versus alternatives like 'steampipe_table_show' or 'steampipe_query,' nor does it provide exclusion criteria.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

steampipe_table_showB

Get detailed information about a specific Steampipe table, including column definitions, data types, and descriptions.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesThe name of the table to show details for. Can be schema qualified (e.g. 'aws_account' or 'aws.aws_account').
schemaNoOptional schema name. If provided, only searches in this schema. If not provided, searches across all schemas.

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It describes the tool's function but lacks details on behavioral traits such as error handling (e.g., what happens if the table doesn't exist), performance characteristics, or output format. This is a significant gap for a tool with no annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, well-structured sentence that efficiently conveys the tool's purpose and scope without unnecessary words. It's front-loaded with the main action and resource, making it easy to understand at a glance.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's moderate complexity (2 parameters, no output schema, no annotations), the description is minimally adequate. It covers the purpose but lacks behavioral context and output details, which are important for a tool that retrieves metadata. Without annotations or output schema, more completeness would be beneficial.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema fully documents both parameters ('name' and 'schema') with clear descriptions. The description doesn't add any parameter-specific information beyond what's in the schema, such as examples or constraints. Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Get detailed information') and resource ('specific Steampipe table'), and specifies the scope of information returned ('including column definitions, data types, and descriptions'). It distinguishes from the sibling 'steampipe_table_list' by focusing on details for a single table rather than listing tables. However, it doesn't explicitly contrast with 'steampipe_query' which might also return table information through queries.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage when detailed metadata about a specific table is needed, but doesn't provide explicit guidance on when to use this tool versus alternatives like 'steampipe_table_list' for listing tables or 'steampipe_query' for querying data. It mentions the resource type ('Steampipe table') but lacks context on prerequisites or exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 5 tool updates
    • First observedsteampipe_plugin_list
    • First observedsteampipe_plugin_show
    • First observedsteampipe_query
    • First observedsteampipe_table_list
    • First observedsteampipe_table_show

TDQS

A3.9/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a clearly distinct purpose with no overlap: listing plugins vs. showing plugin details vs. executing queries vs. listing tables vs. showing table details. The descriptions reinforce these distinctions, making misselection unlikely.

Naming Consistency5/5

All tools follow a consistent 'steampipe_' prefix with a clear verb_noun pattern (plugin_list, plugin_show, query, table_list, table_show). This uniformity makes the tool set predictable and easy to navigate.

Tool Count5/5

Five tools is well-scoped for the server's purpose of interacting with Steampipe. It covers plugin management, query execution, and table metadata without being overly sparse or bloated, with each tool earning its place.

Completeness4/5

The tool set provides strong coverage for querying and exploring Steampipe data, including plugin and table metadata. A minor gap exists in lacking direct plugin installation or configuration management tools, but agents can work around this using existing query capabilities.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Connects AI assistants to Supabase projects, enabling them to manage tables, query data, deploy Edge Functions, handle migrations, and access project resources through natural language commands.
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Connects AI assistants to cloud and SaaS logs via Tailpipe, enabling natural language querying and analysis of log data.
    16
    7
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI assistants to query databases using natural language, with automatic schema discovery and SQL compilation.
    995
    3,162
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Connects AI assistants to Turbot Guardrails for natural language exploration, analysis, and automation of cloud governance.
    15
    4
    Apache 2.0