Postgres MCP Pro
3,352 starsCrystalDBA's community Postgres MCP server: beyond schema browsing and SQL execution it ships DBA-grade tools — explain_query for execution plans (simulatable with hypothetical indexes), get_top_queries for slowest queries, analyze_workload_indexes/analyze_query_indexes for index recommendations, and analyze_db_health for comprehensive health checks. --access-mode switches between unrestricted (read/write) and restricted (read-only plus execution-time limits).
- First published:2025-03-24
- data as of:
- 2026-09-30
- Licence:
- MIT
- Transport:
- stdio
- Primitives exposed:
- tools
What it can touch
Against the Postgres database at DATABASE_URI: restricted mode limits operations to read-only transactions with execution-time constraints; unrestricted mode can modify data and schema (officially positioned for development environments). The connection string contains credentials. Health and index tools read system views like pg_stat_statements.
Risk
The README's own example config defaults to --access-mode=unrestricted — copying it verbatim hands full DDL/DML authority to the agent; an injected one can drop tables, rewrite data or plant trigger functions. The project itself says restricted is the production posture. A leaked DATABASE_URI is a compromised database.
Install prompt
從官方倉庫 README 取得設定片段(Docker 方式:執行 crystaldba/postgres-mcp 映像並以 DATABASE_URI 環境變數傳入連線字串,以 --access-mode 選擇 restricted 或 unrestricted),加進客戶端設定後重啟。生產環境建議 restricted。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.