MCP Database Doctor

io.github.petrovicistefanv0.1.1更新於 Oct 9, 2026

Offline PostgreSQL query, migration and EXPLAIN diagnostics for AI agents.

已驗證STDIO僅桌面Developer ToolsDatabases

概覽

AI 產生的概覽

讓助理在離線狀態下靜態審查 PostgreSQL SQL、遷移、索引候選與提供的 EXPLAIN JSON 計畫,不需要資料庫憑證。

功能
提供五個本機工具:analyze_query 檢查 SQL 反模式,check_migration 檢查破壞性 DDL、索引鎖定、條件約束、重寫與交易風險,suggest_indexes 提出保守的 DDL 候選,explain_plan 分析提供的 EXPLAIN JSON 計畫,health_report 彙整所提供的素材。報告包含 code、severity、message、recommendation 與語句編號。它不會連線資料庫、不會執行語句,也不會自動修正。
適用情境
適合助理起草或修改 PostgreSQL 查詢與遷移、並希望在實際執行前取得規則式二次審查的情境。適用於程式碼審查與遷移前檢查,前提是你能自行提供 SQL 或 EXPLAIN JSON 計畫。它不能取代在真實資料庫上的測試。
執行需求
以 npx mcp-database-doctor 啟動的本機 stdio 程序,需要 Node.js 22.18 或更新版本(建議 Node 24)。不需要帳號、API 金鑰或資料庫憑證。選用的託管 HTTP 方式需要先建置、設定 CONTROL_PLANE_URL,並使用 Authorization Bearer 權杖。
安裝前請注意
檢查結果是啟發式審查提示,並非保證:no_rules_triggered 不代表安全、有效率或 SQL 合法,未發現問題也不等於可以執行遷移。索引建議僅為候選,絕不會被套用。託管方式需要 Authorization Bearer 權杖,並透過控制平面保留配額單位,該控制平面只會看到 product、requestId 與 units;SQL 與計畫保留在託管主機上。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 MCP Database Doctor,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

MCP Database Doctor

Offline PostgreSQL diagnostics for AI coding agents. Review SQL, risky migrations, candidate indexes and supplied EXPLAIN JSON plans without database credentials or executing statements.

Status: 0.1.0 MVP. Static rules are heuristic: no_rules_triggered does not mean safe, performant or valid PostgreSQL. No telemetry, remote analysis, credentials or automatic fixes.

Install in your AI client

Works with any MCP client over stdio; no account or API key needed for the local server.

Claude Code

sh
claude mcp add database-doctor -- npx -y mcp-database-doctor

Codex CLI

sh
codex mcp add database-doctor -- npx -y mcp-database-doctor

Claude Desktop, Cursor, Windsurf, Cline, Gemini CLI — add to the client's MCP config (claude_desktop_config.json, ~/.cursor/mcp.json, ~/.codeium/windsurf/mcp_config.json, Cline MCP settings, ~/.gemini/settings.json):

json
{  "mcpServers": {    "database-doctor": {      "command": "npx",      "args": [        "-y",        "mcp-database-doctor"      ]    }  }}

VS Code / GitHub Copilot — .vscode/mcp.json:

json
{  "servers": {    "database-doctor": {      "type": "stdio",      "command": "npx",      "args": [        "-y",        "mcp-database-doctor"      ]    }  }}

Zed — settings.json:

json
{  "context_servers": {    "database-doctor": {      "command": "npx",      "args": [        "-y",        "mcp-database-doctor"      ]    }  }}

Tools

ToolInputOutput
analyze_querysqlSQL anti-patterns with severity and recommendations
check_migrationsqlDestructive DDL, index locking, constraints, rewrite and transaction risks
suggest_indexessql, optional existingIndexes: [{table, columns}]Conservative DDL candidates; not applied
explain_planplan as a JSON stringLarge sequential scans, row estimate errors, sort spills, high loops
health_reportoptional queries, migrations, plans arrays; at least one requiredAggregate review of supplied artifacts only

Reports include code, severity, message, recommendation, and statement numbers for SQL. No synthetic database health score.

Development

Node.js >=22.18 (Node 24 recommended).

sh
npm installnpm run checknpm testnpm run buildnpm run test:integrationnpm pack --dry-run

Core tests run without installed dependencies using Node's native TypeScript stripping. Vitest integration tests exercise the official MCP client over stdio after build. CI runs both. Generate and commit a package-lock.json after the first successful dependency installation; current checkout does not include one because npm access was blocked in the implementation environment.

Claude Code / Cursor

Build locally first. Copy examples/mcp.json into your client's MCP configuration and replace the absolute checkout path:

json
{  "mcpServers": {    "database-doctor": {      "command": "node",      "args": ["/absolute/path/mcp-database-doctor/dist/server.js"]    }  }}

Claude Code CLI alternative:

sh
claude mcp add database-doctor -- node /absolute/path/mcp-database-doctor/dist/server.js

Launch with npx -y mcp-database-doctor.

Suggested agent instruction: "Before proposing database changes, call check_migration. Review slow queries with analyze_query and supplied EXPLAIN JSON. Treat index DDL as candidates requiring workload validation."

Examples

check_migration({"sql":"BEGIN; CREATE INDEX CONCURRENTLY ON users(email); COMMIT;"}) identifies an invalid transaction context.

analyze_query({"sql":"SELECT * FROM users OFFSET 50000"}) flags projection and deep pagination.

explain_plan({"plan":"[{\"Plan\":{\"Node Type\":\"Seq Scan\",\"Plan Rows\":20000}}]"}) flags a scan for review; it does not claim an index is necessarily better.

For a real database, obtain plans yourself on a safe test environment: EXPLAIN (FORMAT JSON) SELECT .... EXPLAIN ANALYZE executes the statement; this server never runs it.

Limits and interpretation

  • PostgreSQL-first, not a full SQL parser. Comments and string/dollar literals are masked. Quoted identifiers are masked to avoid keyword confusion.
  • SQL inside stored procedures, DO blocks and dynamic strings is not analyzed. Complex CTEs, nested scopes, aliases, quoted/schema names and unusual DDL can produce false positives or missed findings.
  • Index inference intentionally supports one unquoted table without joins/subqueries. No schema metadata, statistics, foreign-key index analysis or composite-index optimization. Existing indexes only suppress candidates when their supplied leading column matches; partial/expression indexes need manual review.
  • Migration checks assume the supplied script defines transaction boundaries. If a migration framework wraps scripts externally, provide its BEGIN/COMMIT context when checking concurrent indexes.
  • 100000 characters per SQL, 1 MB per plan string, 100 artifacts per report, 10000 plan nodes. These are analysis limits, not a substitute for host transport limits.
  • Findings are review prompts. Absence of a finding is not authorization to run a migration.

Hosted path (quotas via control plane)

Local MCP stays free and offline. Quotas apply only on a hosted HTTP process that reserves units on mcp-control-plane before analysis. Build first (npm run build), then:

sh
cp .env.example .env   # set CONTROL_PLANE_URLnpm run start:hosted   # default 127.0.0.1:3103
MethodPathBody
GET/healthLiveness
POST/v1/analyze-query{ "requestId", "sql" }
POST/v1/check-migration{ "requestId", "sql" }
POST/v1/suggest-indexes{ "requestId", "sql", "existingIndexes"? }
POST/v1/explain-plan{ "requestId", "plan" }
POST/v1/health-report{ "requestId", "queries"?, "migrations"?, "plans"? }

Requires Authorization: Bearer mcp_…. SQL and plans stay on the hosted host; control-plane sees only product, requestId, and units. No database credentials are accepted.

Commercial roadmap

Free: local query/migration/plan analysis. Pro later: history, before/after comparisons, CI policies and advanced recommendations. Team later: shared policies and centralized reports. Hosted quotas use the control-plane path above; local counters are not used for paid enforcement.

Validation status

  • 53 core tests passed in the implementation environment.
  • Typecheck/build/MCP stdio integration: configured, not run locally (npm registry returned HTTP 403).
  • Real PostgreSQL and two actual AI hosts: pending; configuration files do not constitute host integration validation.

References

MIT license.

來源:README.md,提交 14504f4

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 9, 2026