56
/ 100
1 month ago
glama

celp-mcp

Celp-MCP enables natural-language analytics over SQL, MongoDB, and Databricks warehouses through MCP-compatible clients, converting questions into multi-step database plans and returning markdown reports.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: CELP_API_KEY, DATABASE_PASSWORD, DATABRICKS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical4 high2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalmysql2@3.9.3GHSA-4rch-2fh8-94vw

MySQL2 for Node Arbitrary Code Injection

criticalmysql2@3.9.3GHSA-fpw7-j2hg-69v5

mysql2 Remote Code Execution (RCE) via the readCodeFor function

high@modelcontextprotocol/sdk@1.11.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.11.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.11.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretCELP_API_KEYthe environment variables for your database + .
configDATABASE_HOSTPostgres/MySQL DATABASE_TYPE · · DATABASE_USER · DATABASE_PASSWORD · DATABASE_NAME
configDATABASE_NAMEPostgres/MySQL DATABASE_TYPE · DATABASE_HOST · DATABASE_USER · DATABASE_PASSWORD ·
🔐 secretDATABASE_PASSWORDPostgres/MySQL DATABASE_TYPE · DATABASE_HOST · DATABASE_USER · · DATABASE_NAME
configDATABASE_PORT"": "5432",
configDATABASE_TYPEPostgres/MySQL · DATABASE_HOST · DATABASE_USER · DATABASE_PASSWORD · DATABASE_NAME
configDATABASE_USERPostgres/MySQL DATABASE_TYPE · DATABASE_HOST · · DATABASE_PASSWORD · DATABASE_NAME
configDATABRICKS_CATALOGDatabricks DATABASE_TYPE=databricks · DATABRICKS_HOST · DATABRICKS_TOKEN · DATABRICKS_HTTP_PATH ·
configDATABRICKS_HOSTDatabricks DATABASE_TYPE=databricks · · DATABRICKS_TOKEN · DATABRICKS_HTTP_PATH · DATABRICKS_CATALOG
configDATABRICKS_HTTP_PATHDatabricks DATABASE_TYPE=databricks · DATABRICKS_HOST · DATABRICKS_TOKEN · · DATABRICKS_CATALOG
configDATABRICKS_PORT
configDATABRICKS_SCHEMA
🔐 secretDATABRICKS_TOKENDatabricks DATABASE_TYPE=databricks · DATABRICKS_HOST · · DATABRICKS_HTTP_PATH · DATABRICKS_CATALOG
configDATABRICKS_USER
configDONT_USE_DB_ENVS
configMONGO_AUTH_SOURCE
configMONGO_CONNECT_TIMEOUT_MS
configMONGO_MAX_POOL_SIZE
configMONGO_READ_PREFERENCE
configMONGO_REPLICA_SET
configMONGO_SERVER_SELECTION_TIMEOUT_MS
configMONGO_SSL
configMONGO_URLMongoDB Either the five above or a single
configPG_DISABLE_SSL"": "true",
configSTREAMING_API_URLTo override (e.g., when self-hosting) set .
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/celpai-celp-mcp-1vphkh)](https://m8ven.ai/mcp/celpai-celp-mcp-1vphkh)
commit: ad2329d81d5ab1af78fcf1d27655aa66ccdf5313
code hash: 1ac1cc72631977c469279a74ece7b8520ee7f324f51979d9d0606794fdd5dd83
verified: 6/23/2026, 10:23:52 AM
view raw JSON →