hs-sql-agent
.NET SQL Agent MCP server featuring raw SQL input, strict AST validation, and an embedded Admin UI. Eliminates LLM hallucinations and security risks across 6 major databases.
Install / Use
claude mcp add tse-wei-chen -- npx -y github:tse-wei-chen/hs-sql-agentIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of hs-sql-agent
hs-sql-agent scores 83/100 on our quality scale, 751st of 1,002 Security skills we index.
Its MCP Server is 8.1 KB long, well organised into 13 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so hs-sql-agent is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hs-sql-agent compared with similar skills
All 4 of these similar skills score higher than hs-sql-agent; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hs-sql-agent (this skill)by tse-wei-chen | 83 | 10 | 1d ago | MCP Server |
| claude-memby thedotmack | 100 | 95.1k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 87.5k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.7k | today | CLAUDE.md |
Frequently asked questions
- How do I install hs-sql-agent?
- Run
claude mcp add tse-wei-chen -- npx -y github:tse-wei-chen/hs-sql-agent. The install tabs above show the steps for each supported agent. - Which AI agents does hs-sql-agent work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is hs-sql-agent safe to use?
- It is Apache-2.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hs-sql-agent still maintained?
- The repository was last updated yesterday, so hs-sql-agent is actively maintained.
Skill content
View source on GitHubhs-sql-agent
<img width="1000" height="500" alt="coverImage" src="https://github.com/user-attachments/assets/e317cee2-7bf3-4b11-94b9-4fdeedb29689" />Turn trusted SQL into governed MCP tools for AI agents.
hs-sql-agent is an open-source SQL-to-MCP tool factory and governed SQL execution boundary. Define parameterized SQL in the Admin UI, publish it as a typed MCP tool, and let AI agents supply only the arguments — without writing a new C# method or redeploying your MCP server for every database operation.
Every published tool still runs through the same fail-closed SQL compiler, per-key database/table policy, runtime limits, audit trail, and Safe DML approval controls. Raw SQL tools remain available for cases where an agent genuinely needs flexible ad-hoc querying.
It supports PostgreSQL, MySQL, SQL Server, Oracle, SQLite, and Firebird and can run as the complete first-party server with its Admin UI or be embedded into an existing ASP.NET Core application.
Publish SQL as an MCP tool
Instead of teaching the model to regenerate the same query every time, define the SQL shape once:
SELECT id, total, status
FROM orders
WHERE customer_id = {{ customerId }}
AND status = {{ status }}
Declare customerId and status in Runtime → Custom Tools, test the draft, then publish it. hs-sql-agent exposes the published definition to MCP clients as a named tool with a generated JSON input schema.
The agent sees a contract conceptually like:
get_customer_orders(
customerId: number,
status: string
)
The SQL template stays engineer-defined. Placeholders are value parameters only; identifiers and arbitrary SQL fragments cannot be injected through them.
Published custom tools can be Query or DML tools. Query tools use the same typed compiler and access-policy path as built-in SQL execution. DML tools use the same preview → approval → revalidation → commit protocol, including atomic multi-statement transactions.
Why hs-sql-agent?
- SQL-to-MCP Custom Tools — Turn engineer-reviewed SQL templates into discoverable MCP tools with typed parameters, descriptions, draft/test/publish lifecycle, revisions, rollback, and database binding.
- Fail-closed SQL compiler — Unsupported or unproven syntax is rejected instead of being silently rewritten with different semantics.
- Closed F# compiler core — SQL enters a closed discriminated-union AST and advances through unforgeable
parsed → bound → canonical → validated → executablecompiler stages. - Six database providers — PostgreSQL, MySQL, SQL Server, Oracle, SQLite, and Firebird with provider-aware validation and lowering.
- Safe DML — Read-only impact preview, one-time approval challenge, commit-time row-set revalidation, and explicit human approval through MCP Elicitation or an approval provider.
- Governed access — Per-key database binding, table whitelisting, rate limits, execution limits, roles, policies, and audit records.
- Flexible hosting — Run the packaged server and Admin UI, use the standard ASP.NET Core host, or compose advanced integrations from modular capabilities.
- Production observability — Prometheus metrics, OpenTelemetry/OTLP, audit retention, and webhook/SIEM delivery.
SQL support is intentionally bounded by proven semantics. See the SQL Support Reference for the current contract.
Quick Start
cp .env.example .env
# Set HMAC_KEY and JWT_KEY to unique secrets of at least 32 bytes.
docker compose up -d
Open the Admin UI at http://localhost:8080.
For production settings and deployment options, use the Configuration Reference and Deployment Guide.
Use with an MCP client
Set MCP_PUBLIC_ENDPOINT to the externally reachable MCP URL, including /mcp, before issuing production keys.
Then open Runtime → MCP Keys in the Admin UI and issue a key. The one-time Save and connect dialog generates ready-to-paste configuration for Claude Desktop, Cursor, Visual Studio Code, and generic Streamable HTTP clients.
The plaintext secret is shown only once. See MCP Client Onboarding for client setup, compatibility, and DML Elicitation requirements.
Use from .NET
For the same batteries-included composition as the official Docker host, install HsSqlAgent.Hosting:
dotnet add package HsSqlAgent.Hosting
using HsSqlAgent.Hosting;
var builder = WebApplication.CreateBuilder(args);
builder.AddHsSqlAgentStandardHost();
var app = builder.Build();
app.UseHsSqlAgentStandardHost();
await app.RunAsync();
Use HsSqlAgent.Server directly only when you need custom authentication, middleware ordering, approval providers, UI, or capability composition.
See the ASP.NET Core Integration Guide and the HsSqlAgent.Hosting package README for the full integration contract.
How SQL execution works
- Authenticate the MCP key and establish its database, table, tool, and execution-policy scope.
- For Custom Tools, resolve the published definition and render declared value parameters into the engineer-defined SQL template.
- Parse SQL into the closed compiler model and bind source semantics.
- Normalize and validate syntax, semantics, capabilities, and policy.
- Render only an executable typestate into provider-specific SQL and parameters.
- Execute within configured runtime limits.
The compiler core is provider-driver-free: parsing, validation, normalization, capability proof, lowering, and rendering are kept separate from database drivers and runtime execution.
For DML, hs-sql-agent first builds a read-only impact preview, binds approval to the validated plan and matched row set, requires explicit human approval, and revalidates inside the commit transaction before applying the mutation.
Custom SQL tools pass through the same compiler, access policy, and execution limits as built-in tools.
SQL Execution Flow
<picture> <source media="(prefers-color-scheme: dark)" srcset="miscellaneous/diagram-black.png"> <source media="(prefers-color-scheme: light)" srcset="miscellaneous/diagram-light.png"> <img alt="SQL Execution Flow" src="miscellaneous/diagram-light.png"> </picture>DML Approval Prompt
<img width="1199" height="890" alt="dml-approval-prompt" src="https://github.com/user-attachments/assets/ebd40519-e0b3-43d6-9e83-24238f3c00d6" />Documentation
The documentation site is the source of truth for detailed configuration, integration, SQL capability, security, and operations guidance:
- Documentation Home
- Quick Start
- Custom Tools
- ASP.NET Core Integration
- SQL Support Reference
- Security Overview
Contributing
See CONTRIBUTING.md and the Architecture and Contribution Flow.
License
Related Skills
claude-mem
95.1kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
87.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.7k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
