Skip to main content
Glama
620,636 tools. Updated 2026-09-29 03:51

"Giving Claude full access to SQL Server for free" matching MCP tools:

  • Search the MITRE D3FEND catalog of defensive techniques by keyword, tactic, or targeted artifact. Default response is SLIM (drops `uri` from each row — saves ~60 chars/row, ~30% on popular drills); pass include='full' for the verbose record. Pass exclude_id when chaining from d3fend_defense_lookup to skip self in sibling-artifact searches. Use to discover defenses applicable to a given threat model — e.g. 'what defenses harden access tokens?' (tactic=Harden + artifact='Access Token'). Drill into d3fend_defense_lookup with any returned defense_id for the ATT&CK technique mappings. Free: 30/hr, Pro: 500/hr. Returns {query, total, results [{defense_id, label, uri (only when include=full), parent_label, tactic, artifact}], next_calls}.
    ConnectorNo auth
  • Run a read-only SQL query against an app's Postgres database and return up to 200 result rows. SELECT only — writes and DDL (INSERT/UPDATE/DELETE/ALTER/DROP/…) are rejected server-side; use vibekit_chat or vibekit_submit_task to have the agent make data or schema changes. Call vibekit_db_schema first to learn the tables. SQL string, max 5000 chars.
    ConnectorNo auth
  • Generate a Personal Access Token (PAT) for browser-free auth. Requires you to be logged in already (brainkb_login or brainkb_globus_login). The token is shown ONCE and never again — copy it and set it as BRAINKB_TOKEN in your MCP/skill config; then no login or browser is needed until it expires. `name`: a label so you can tell tokens apart (e.g. 'laptop'). `days`: lifetime (default 90, server-capped). Treat the returned token like a password.
    ConnectorNo auth
  • [free] Describe this connector: flagship-first tools layer (search/answer as the front door), how to install (Claude Code / Cursor / npm), free vs paid tiers, and discovery URLs. Call this first.
    ConnectorNo auth
  • Get metadata for a specific CBS Netherlands statistical table by its identifier (e.g. "83583NED"). Returns full title, description, time period covered (e.g. 2010–2024), publication frequency, number of records, data source, output status (provisional/final), and the API URL for data access. Use catalog_search first to discover table identifiers. Source: opendata.cbs.nl — CC BY 4.0, no auth, unlimited free access.
    ConnectorNo auth

Matching MCP Servers

  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables unrestricted SQL execution (DDL/DML) on PostgreSQL databases, allowing AI agents to create, read, update, and delete data with zero query filtering.
    1
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to execute any SQL command (including DDL/DML) on a PostgreSQL database with zero restrictions, allowing full database control and dynamic database switching.
    1
    -

Matching MCP Connectors

  • Validate ClaudeBot and Claude-SearchBot IP addresses. Remote MCP validate_ip tool.

  • Gluten-free

  • Describe this MCP server: what it wraps, the fact that it is completely free with no API key, no signup and no auth, the fair-use rate limit, the full tool list, and links to hackmyip.com and its API docs. Call this when the user asks what this server can do, whether it costs anything, or where the data comes from.
    ConnectorNo auth
  • Publish a per-purchase listing for any asset type (data, services, investments, digital assets, real estate, products, documents, jobs & work, compute & API access, access & memberships, capital & funding, IP & rights, and more). verticalmarketplace.ai is a ZERO-STORAGE BROKER: it never stores what you sell — it relays your deliverable live from your verified delivery endpoint at purchase time. If you have a server, register + verify that endpoint with set_delivery_endpoint. No server (chat-only agent like ChatGPT, Claude, Grok, Gemini)? Call sell_data anyway: the listing is accepted as PENDING and the response carries a claimUrl — hand that exact link to your human, who verifies the delivery endpoint (a ready-to-paste template is on that page) and, only for priced listings, connects Stripe. The listing goes live the moment the endpoint verifies. Never invent a claimUrl; only relay the one returned. Stripe is only for payouts on priced listings; free ($0) listings never need it. Provide metadata only (title, description, a small scrubbed preview, price). Do NOT send the deliverable itself. You keep 95% on everyday sales from $20 to $49,999.99 under the year-one founding rate locked through 2027-06-30; see the full schedule at GET /api/meta. Listing is free (price_cents 0 = free). consent=true confirms you own what you list and may sell it; the attestation is asset-type-specific. Personal health data is NOT accepted here — use the list_health_data tool, which runs the required signed consent flow.
    ConnectorNo auth
  • Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
    ConnectorNo auth
  • Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
    ConnectorNo auth
  • Add a published FindAgent agent you're ENTITLED to (free, or paid + purchased) as a hosted MCP connector. Returns the per-client connector config — the hosted server URL (mcp.findagent.cloud/agents/<slug>), a drop-in mcp.json block, a Claude Code command, and the one-time FindAgent sign-in steps. Free agents are always available; a paid agent you don't own returns purchase_required pointing at findagent_buy_agent. An unknown or unpublished slug returns a needs_input result pointing back to findagent_browse_agents. This returns config only — the actual install happens when you complete the sign-in in your client. If the slug is an MCP SERVER LISTING rather than an agent FindAgent runs, it returns status external_mcp_server with the PROVIDER's own connect details (their URL, or the command that starts the server on the user's machine) and no FindAgent sign-in — FindAgent is not in that connection.
    ConnectorOAuth
  • Find and list your automation runs — use for "how did my tests go", "what failed recently", "show me the runs for suite X", or to locate a run when the user describes it instead of giving an id. Every filter is applied by the SERVER across your whole history, so a suite or a session id from weeks ago is found just as reliably as one from today. `total` is the true number of matching runs; `runs` is one page of them, so page with `offset` rather than assuming the first page is everything. Pass `search` to hunt for a session id — the short 8-character form shown in the UI and the full id both work. For pass rates and aggregate breakdowns use automation_report instead of tallying these rows.
    ConnectorOAuth
  • Claim a Fixter investigation for the calling user and fetch its full transcript. Accepts the investigation's UUID or its public slug (e.g. 'happy-otter-42'). This CLAIMS the investigation (records the caller as claimant) — only call it when the user intends to work on the investigation; use get_investigation_brief for read-only access. Returns JSON: id, publicSlug, headline, flow, channelId, threadTs, createdAt, claimedBy, sessionEntries (the raw Claude Agent SDK transcript of the original investigation).
    ConnectorAPI key
  • Query the LOCAL CACHE of every page this server has fetched and every search it has run. Check here BEFORE re-fetching or re-searching — a hit is instant and free while a fresh fetch costs 5-60s. Use query for full-text search (works for Chinese substrings and English words), get to pull a page's full cached content, stats for counts, clear to delete rows.
    ConnectorNo auth
  • Request a free evaluation key (qd_...): no card, no account — the key is emailed to the address given, never returned in this response. It unlocks 10 successful calls per UTC day. Ask the human for their email address first and send marketing_opt_in=true only with their explicit consent. Full access is $99.90/month with a 3-day free trial, checkout link comes back in any quota-exhausted error.
    ConnectorNo auth
  • FREE taster: the full-quality liquidation forecast for SOL, no delay and nothing withheld. Use it to check the calibration before paying for coverage of the other ~345 symbols. Free.
    ConnectorNo auth
  • Free. One full risk card (the exact paid mint_risk_card shape) for a mint aged >= 300 s with >= 3 buys, delayed. Use it to see every field before paying; the server picks the mint, so it is not a check on yours. No arguments.
    ConnectorNo auth
  • How an AI agent gets access to The Continental: the free Porch pass (no human needed: hashcash + Ed25519), and membership through an operator (price, limits, the three steps they take, the text to forward to them). Also how to configure this server once you have a key. Call this first if you have no key.
    ConnectorNo auth
  • Get the calling API key's own redacted metadata (id, name, key_prefix, environment, scopes, last_used_at, revoked_at, created_at) for agent self-inspection. Never returns the key hash or full secret. Requires API-key auth — a JWT session has no single-key context (returns 400 api_key_required). ACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.
    ConnectorNo auth
  • Find observation variables (traits) by name, trait class, ontology term, or free-text query. Free-text queries are ranked against the returned set and may resolve to ontology URIs when the server advertises them. When the upstream total exceeds loadLimit, the full result set is materialized as a dataframe — query it with brapi_dataframe_query (SQL).
    ConnectorNo auth