Agentic Research

Postgres MCP Pro

3,352 stars

CrystalDBA's community Postgres MCP server: beyond schema browsing and SQL execution it ships DBA-grade tools — explain_query for execution plans (simulatable with hypothetical indexes), get_top_queries for slowest queries, analyze_workload_indexes/analyze_query_indexes for index recommendations, and analyze_db_health for comprehensive health checks. --access-mode switches between unrestricted (read/write) and restricted (read-only plus execution-time limits).

First published:2025-03-24
data as of:
2026-09-30
Licence:
MIT
Transport:
stdio
Primitives exposed:
tools

What it can touch

Against the Postgres database at DATABASE_URI: restricted mode limits operations to read-only transactions with execution-time constraints; unrestricted mode can modify data and schema (officially positioned for development environments). The connection string contains credentials. Health and index tools read system views like pg_stat_statements.

Risk

The README's own example config defaults to --access-mode=unrestricted — copying it verbatim hands full DDL/DML authority to the agent; an injected one can drop tables, rewrite data or plant trigger functions. The project itself says restricted is the production posture. A leaked DATABASE_URI is a compromised database.

Install prompt

從官方倉庫 README 取得設定片段(Docker 方式:執行 crystaldba/postgres-mcp 映像並以 DATABASE_URI 環境變數傳入連線字串,以 --access-mode 選擇 restricted 或 unrestricted),加進客戶端設定後重啟。生產環境建議 restricted。

Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.

Official source Source(3,352 ★)
Compatible with