MySQL (berthojoris) MCP Server

@berthojoris/mcp-mysql-server npm v1.43.2

Published by @berthojoris — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.

MySQL integration with dynamic per-project permissions.

Trust grade
A
96/100
Last scanned get badge →
Trust
A · 96/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
Moderate
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 96/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−3 capability blast radius (moderate) — client exposure if the model is manipulated
−1 publisher verification (public source) — no provenance, but the source is public and inspectable

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 0

✓ No findings. The scan raised nothing on this surface — see Coverage for how deep it could look.

Tools 88

Each tool and what it can reach — statically extracted from the published source.

  • analyze_queryreads sensitive data
  • execute_in_transactionreads sensitive data
  • repair_queryreads sensitive data
  • add_check_constraintno sensitive capability
  • add_foreign_keyno sensitive capability
  • add_unique_constraintno sensitive capability
  • alter_tableno sensitive capability
  • alter_viewno sensitive capability
  • analyze_indexno sensitive capability
  • analyze_tableno sensitive capability
Show 78 more tools ↓
  • begin_transactionno sensitive capability
  • bulk_deleteno sensitive capability
  • bulk_insertno sensitive capability
  • bulk_updateno sensitive capability
  • check_tableno sensitive capability
  • commit_transactionno sensitive capability
  • create_fulltext_indexno sensitive capability
  • create_indexno sensitive capability
  • create_recordno sensitive capability
  • create_stored_procedureno sensitive capability
  • create_tableno sensitive capability
  • create_triggerno sensitive capability
  • create_viewno sensitive capability
  • cursor_execute_requestno sensitive capability
  • delete_recordno sensitive capability
  • describe_connectionno sensitive capability
  • drop_constraintno sensitive capability
  • drop_foreign_keyno sensitive capability
  • drop_fulltext_indexno sensitive capability
  • drop_indexno sensitive capability
  • drop_stored_procedureno sensitive capability
  • drop_tableno sensitive capability
  • drop_triggerno sensitive capability
  • drop_viewno sensitive capability
  • execute_ddlno sensitive capability
  • execute_seed_planno sensitive capability
  • execute_stored_procedureno sensitive capability
  • execute_write_queryno sensitive capability
  • export_query_to_csvno sensitive capability
  • export_table_to_csvno sensitive capability
  • find_tables_by_keywordno sensitive capability
  • flush_tableno sensitive capability
  • fulltext_searchno sensitive capability
  • generate_seed_previewno sensitive capability
  • get_all_tables_relationshipsno sensitive capability
  • get_column_statisticsno sensitive capability
  • get_database_summaryno sensitive capability
  • get_fulltext_infono sensitive capability
  • get_fulltext_statsno sensitive capability
  • get_index_infono sensitive capability
  • get_optimization_hintsno sensitive capability
  • get_schema_erdno sensitive capability
  • get_schema_rag_contextno sensitive capability
  • get_stored_procedure_infono sensitive capability
  • get_table_sizeno sensitive capability
  • get_table_statusno sensitive capability
  • get_transaction_statusno sensitive capability
  • get_trigger_infono sensitive capability
  • get_view_infono sensitive capability
  • infer_seed_rulesno sensitive capability
  • list_all_toolsno sensitive capability
  • list_constraintsno sensitive capability
  • list_databasesno sensitive capability
  • list_foreign_keysno sensitive capability
  • list_indexesno sensitive capability
  • list_stored_proceduresno sensitive capability
  • list_tablesno sensitive capability
  • list_triggersno sensitive capability
  • list_viewsno sensitive capability
  • optimize_fulltextno sensitive capability
  • optimize_tableno sensitive capability
  • plan_seed_datano sensitive capability
  • read_changelogno sensitive capability
  • read_recordsno sensitive capability
  • read_table_schemano sensitive capability
  • repair_tableno sensitive capability
  • rollback_transactionno sensitive capability
  • run_select_queryno sensitive capability
  • search_data_across_tablesno sensitive capability
  • search_schemano sensitive capability
  • seed_from_templateno sensitive capability
  • show_create_procedureno sensitive capability
  • show_create_triggerno sensitive capability
  • show_create_viewno sensitive capability
  • test_connectionno sensitive capability
  • truncate_tableno sensitive capability
  • update_recordno sensitive capability
  • validate_seed_integrityno sensitive capability

What this scan could not see

Versions 2

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v1.43.2 latest A 96/100 0 1.13.0 2026-08-25
v1.43.0 A 100/100 0 1.5.0 2026-07-22

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 96/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/berthojoris-mcp-mysql-server/badge.svg)](https://mcptrustchecker.com/registry/berthojoris-mcp-mysql-server)
HTML
<a href="https://mcptrustchecker.com/registry/berthojoris-mcp-mysql-server"><img src="https://mcptrustchecker.com/registry/berthojoris-mcp-mysql-server/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/berthojoris-mcp-mysql-server/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @berthojoris/mcp-mysql-server --online

Use the free API → How scoring works

Other implementations of MySQL 69

Independent packages implementing the same tool, scanned with the same engine. Compare all 70 side by side →

More in Databases