Provides read-only SQL query access to Postgres and DuckDB databases via MCP tools, with extensive security hardening for public endpoints.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
amararun
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
SUPABASE_POSTGRESYes — Postgres connection string (use a read-only user)DUCKDB_FILEYes ./data/t20_cricket.duckdb Path to .duckdb fileRATE_LIMITNo 30/minute Per-IP rate limit (SlowAPI format, e.g. 60/hour, 100/minute)PG_STATEMENT_TIMEOUT_MSSet statement_timeout on application roles (matches your )DUCKDB_QUERY_TIMEOUT_MSNo 15000 DuckDB query timeout in millisecondsMAX_JSON_ROWS11. Auto-append LIMIT — queries without an outer LIMIT automatically get one (configurable via / MAX_TSV_ROWS)MAX_TSV_ROWS11. Auto-append LIMIT — queries without an outer LIMIT automatically get one (configurable via MAX_JSON_ROWS / )MAX_RESPONSE_BYTES12. Response size limit — responses exceeding the byte limit are rejected with HTTP 413 (configurable via , default: 1MB)PG_POOL_MINNo 3 Postgres connection pool minimum sizePG_POOL_MAXNo 6 Postgres connection pool maximum sizePG_POOL_ACQUIRE_TIMEOUTNo 15 Seconds to wait for a pool connection before returning 503MAX_CONCURRENT_PER_IPNo 4 Max simultaneous queries per IPMAX_CONCURRENT_GLOBALNo 10 Max simultaneous queries server-wideGLOBAL_RATE_LIMITNo 200/minute Global rate limit across all IPsDUCKDB_MEMORY_LIMITNo 512MB DuckDB memory limitDUCKDB_THREADSNo 2 DuckDB thread limitDUCKDB_TEMP_DIRNo /tmp/duckdb DuckDB temporary directoryDUCKDB_MAX_TEMP_DIR_SIZENo 2GB DuckDB temp directory size capCORS_ALLOW_ORIGINSNo Comma-separated allowed originsLOG_LEVELNo INFO Logging levelAUTH0_DOMAINNo — Auth0 tenant domain (enables /mcp-secure when set)AUTH0_AUDIENCENo — Auth0 API identifierAUTH0_CLIENT_IDNo — Auth0 application client IDAUTH0_CLIENT_SECRETNo — Auth0 application client secretAPI_MONITOR_APP_NAMEAUTH_FAIL_MAX24. Failed-auth rate limiter — in-memory counter blocks IPs after repeated failed JWT attempts on /mcp-secure (configurable via and AUTH_FAIL_WINDOW)AUTH_FAIL_WINDOW24. Failed-auth rate limiter — in-memory counter blocks IPs after repeated failed JWT attempts on /mcp-secure (configurable via AUTH_FAIL_MAX and )License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/amararun-shared-fastapi-database-mcp-ly3xsr)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check