
MCP Database Doctor
io.github.petrovicistefanv0.1.1更新于 Oct 9, 2026
Offline PostgreSQL query, migration and EXPLAIN diagnostics for AI agents.
概览
让助手在离线状态下静态审查 PostgreSQL SQL、迁移、索引候选和提供的 EXPLAIN JSON 计划,无需数据库凭据。
- 功能
- 提供五个本地工具:analyze_query 检查 SQL 反模式,check_migration 检查破坏性 DDL、索引锁、约束、重写和事务风险,suggest_indexes 给出保守的 DDL 候选,explain_plan 分析提供的 EXPLAIN JSON 计划,health_report 汇总所提供的材料。报告包含 code、severity、message、recommendation 和语句编号。它不连接数据库、不执行语句,也不自动修复。
- 适用场景
- 适合助手起草或修改 PostgreSQL 查询与迁移、并希望在实际执行前获得基于规则的二次审查的场景。适用于代码审查和迁移前检查,前提是你能自行提供 SQL 或 EXPLAIN JSON 计划。它不能替代在真实数据库上的测试。
- 运行要求
- 以 npx mcp-database-doctor 启动的本地 stdio 进程,需要 Node.js 22.18 或更高版本(建议 Node 24)。无需账号、API 密钥或数据库凭据。可选的托管 HTTP 方式需要先构建、设置 CONTROL_PLANE_URL,并使用 Authorization Bearer 令牌。
安装
在 SourceWeft 中
- 打开 控制台中的 MCP Database Doctor,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
MCP Database Doctor
Offline PostgreSQL diagnostics for AI coding agents. Review SQL, risky migrations, candidate indexes and supplied EXPLAIN JSON plans without database credentials or executing statements.
Status: 0.1.0 MVP. Static rules are heuristic: no_rules_triggered does not mean safe, performant or valid PostgreSQL. No telemetry, remote analysis, credentials or automatic fixes.
Install in your AI client
Works with any MCP client over stdio; no account or API key needed for the local server.
Claude Code
Codex CLI
Claude Desktop, Cursor, Windsurf, Cline, Gemini CLI — add to the client's MCP config (claude_desktop_config.json, ~/.cursor/mcp.json, ~/.codeium/windsurf/mcp_config.json, Cline MCP settings, ~/.gemini/settings.json):
VS Code / GitHub Copilot — .vscode/mcp.json:
Zed — settings.json:
Tools
Reports include code, severity, message, recommendation, and statement numbers for SQL. No synthetic database health score.
Development
Node.js >=22.18 (Node 24 recommended).
Core tests run without installed dependencies using Node's native TypeScript stripping. Vitest integration tests exercise the official MCP client over stdio after build. CI runs both. Generate and commit a package-lock.json after the first successful dependency installation; current checkout does not include one because npm access was blocked in the implementation environment.
Claude Code / Cursor
Build locally first. Copy examples/mcp.json into your client's MCP configuration and replace the absolute checkout path:
Claude Code CLI alternative:
Launch with npx -y mcp-database-doctor.
Suggested agent instruction: "Before proposing database changes, call check_migration. Review slow queries with analyze_query and supplied EXPLAIN JSON. Treat index DDL as candidates requiring workload validation."
Examples
check_migration({"sql":"BEGIN; CREATE INDEX CONCURRENTLY ON users(email); COMMIT;"}) identifies an invalid transaction context.
analyze_query({"sql":"SELECT * FROM users OFFSET 50000"}) flags projection and deep pagination.
explain_plan({"plan":"[{\"Plan\":{\"Node Type\":\"Seq Scan\",\"Plan Rows\":20000}}]"}) flags a scan for review; it does not claim an index is necessarily better.
For a real database, obtain plans yourself on a safe test environment: EXPLAIN (FORMAT JSON) SELECT .... EXPLAIN ANALYZE executes the statement; this server never runs it.
Limits and interpretation
- PostgreSQL-first, not a full SQL parser. Comments and string/dollar literals are masked. Quoted identifiers are masked to avoid keyword confusion.
- SQL inside stored procedures, DO blocks and dynamic strings is not analyzed. Complex CTEs, nested scopes, aliases, quoted/schema names and unusual DDL can produce false positives or missed findings.
- Index inference intentionally supports one unquoted table without joins/subqueries. No schema metadata, statistics, foreign-key index analysis or composite-index optimization. Existing indexes only suppress candidates when their supplied leading column matches; partial/expression indexes need manual review.
- Migration checks assume the supplied script defines transaction boundaries. If a migration framework wraps scripts externally, provide its BEGIN/COMMIT context when checking concurrent indexes.
- 100000 characters per SQL, 1 MB per plan string, 100 artifacts per report, 10000 plan nodes. These are analysis limits, not a substitute for host transport limits.
- Findings are review prompts. Absence of a finding is not authorization to run a migration.
Hosted path (quotas via control plane)
Local MCP stays free and offline. Quotas apply only on a hosted HTTP process that reserves units on mcp-control-plane before analysis. Build first (npm run build), then:
Requires Authorization: Bearer mcp_…. SQL and plans stay on the hosted host; control-plane sees only product, requestId, and units. No database credentials are accepted.
Commercial roadmap
Free: local query/migration/plan analysis. Pro later: history, before/after comparisons, CI policies and advanced recommendations. Team later: shared policies and centralized reports. Hosted quotas use the control-plane path above; local counters are not used for paid enforcement.
Validation status
- 53 core tests passed in the implementation environment.
- Typecheck/build/MCP stdio integration: configured, not run locally (npm registry returned HTTP 403).
- Real PostgreSQL and two actual AI hosts: pending; configuration files do not constitute host integration validation.
References
- https://ts.sdk.modelcontextprotocol.io/server
- https://www.postgresql.org/docs/current/sql-createindex.html
- https://www.postgresql.org/docs/current/using-explain.html
MIT license.
来源:README.md,提交 14504f4
工具
0版本历史
1- v0.1.1最新Oct 9, 2026
