A secure, read-only MCP server for Microsoft SQL Server with built-in performance monitoring and lock detection.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.MSSQL_ALLOWED_PROCEDURES— Comma-separated whitelist of stored procedures EXEC may call in read-only mode, e.g. dbo.GetReport,dbo.GetCustomerSummary. Empty/unset disables EXEC entirely. - NoMSSQL_DATABASE— Database name - YesMSSQL_DOMAIN— MSSQL_USER SQL Server username (or domain user when is set) - YesMSSQL_ENCRYPT— Use encryption (true/false) false NoMSSQL_ENV_FILE— 1. The path in (explicit override)MSSQL_PASSWORD— password \MSSQL_POOL_MAX— Max pooled connections 10 NoMSSQL_PORT— SQL Server port 1433 NoMSSQL_READ_ONLY— true = read-only allow-list validation. false = write mode: INSERT/UPDATE/DELETE/DDL allowed, but server-level dangerous statements stay blocked true NoMSSQL_REQUEST_TIMEOUT— Query timeout in ms 30000 NoMSSQL_SERVER— localhost \MSSQL_TRUST_CERT— Trust server certificate (true/false) false NoMSSQL_USER— readonly \[](https://m8ven.ai/mcp/piyapatrag-mssql-mcp-server-p73dgd)