secure-mcp-database-crud
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SQLITE_PATH | No | Path to SQLite database file | data/tasks.db |
| MYSQL_POOL_SIZE | No | Number of connections in each MySQL connection pool | 5 |
| DATABASE_BACKEND | No | Database backend: sqlite or mysql | sqlite |
| DB_TIMEOUT_SECONDS | No | Database connection and lock timeout in seconds | 5 |
| CONFIRMATION_SIGNING_KEY | Yes | HMAC signing key for deletion tokens (32+ characters) | |
| CONFIRMATION_TTL_SECONDS | No | Time-to-live for deletion confirmation in seconds | 120 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_tasksB | List tasks with bounded pagination and allowlisted sorting. |
| get_taskA | Get one task by its positive integer ID. |
| prepare_delete_taskA | Return the exact delete target and a short-lived confirmation token. |
| create_taskA | Create one validated task and its audit event atomically. |
| update_taskA | Update only allowlisted task fields, optionally checking the observed version. |
| confirm_delete_taskA | Delete the confirmed task after validating its signed, single-use token. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool targets a distinct operation: create, get, list, update, and a two-step delete with prepare and confirm. There is no functional overlap.
All tool names follow a consistent verb_noun pattern (e.g., create_task, update_task, prepare_delete_task). The naming is clear and predictable.
With 6 tools, the server is well-scoped for task CRUD operations. The count is neither excessive nor insufficient for the domain.
The tool set covers full CRUD functionality plus a secure two-step delete. No obvious missing operations for the stated purpose of secure task management.