Writing
Notes on agents and databases
Working notes on MCP, Oracle, and what actually happens when you put a language model in front of a production schema.
-
How do I stop an AI agent seeing another customer's data in Oracle?
A customer-facing AI agent can be talked into reading another customer's rows. Pin the customer to the MCP connection, where the model can't change it.
-
Why AI coding assistants never finish: the case for 'foostering'
Your AI coding assistant never finishes. It keeps busy with small tasks that get you no closer to done, and at runtime it won't take no for an answer.
-
Are you looking for an alternative to Oracle’s MCP server?
Oracle now ships four ways to put an Oracle database behind MCP. Here is what each one does, what MCP DB Wizard does differently, and how to tell which you need.
-
MCP logging: what the protocol deprecated, and where your server's logs should go
MCP's in-protocol logging is deprecated as of 2026-07-28. What replaces it depends on who reads the log — the client, the operator, your observability stack or an auditor
-
The business risk of a confidently wrong answer from an LLM
The business risk when an LLM answers with the wrong data — what it costs, and why the cost depends on how long nobody notices
-
SQLcl MCP server alternatives for teams that cannot allow ad-hoc SQL
What to evaluate when a run-sql tool is ruled out before the evaluation starts
-
How to stop an AI agent writing SQL against Oracle
You can't stop an agent writing SQL — but you can stop it reaching your database, and the difference is where the credentials live
-
Detecting ad-hoc SQL in Oracle: proving what an AI agent actually sent
Two signals in V$SQL that separate a composed statement from a curated one — distinct SQL_IDs over time, and how many of them collapse onto one FORCE_MATCHING_SIGNATURE
-
How to restrict what an MCP server can do: six places a restriction can live
Client settings, prompts, tool annotations, proxies, database grants and the build — what each one actually survives, and which one is not a promise
-
Curated MCP tools instead of a SQL prompt: a side-by-side
Curated MCP tools instead of a SQL prompt, compared on one ordinary question — eleven places the two diverge, including the three where the SQL prompt genuinely wins
-
Role-based access for an MCP server: necessary, and not sufficient
Database roles decide who may touch what. They cannot tell an agent when to use a tool, or stop it running the right one ten thousand times
-
What people actually mean by a read-only MCP server
A read-only MCP server is shorthand for three different things people want, and only one of them is about writes
-
Least privilege for an Oracle MCP server: choosing the account it connects as
Which Oracle account the server logs in as, why it must never be the one that owns the tables, and the database grants that make the claim real
-
How to limit which Oracle objects an AI agent can reach
Good reasons to expose fewer objects, and the one that bites first is not security
-
What "the agent cannot compose SQL" means on a real schema
Exactly what the claim rules out, what it does not, and how to check which one you have
-
Why the safest SQL prompt is the one that does not exist
Every guard on a SQL-accepting tool is a filter over an infinite input space, and the fix is not a better filter
-
An MCP server with no run-sql tool: what that actually changes
The agent never composes SQL — it calls tools that wrap statements you approved in advance
-
Can I let an AI agent query my production database?
Yes — but the question that matters is what you hand it, not whether you allow it at all
-
How do I make an MCP server read-only?
Three layers, and the one that actually matters is the one that removes the code
-
Prompt injection and your database
A tool that was never generated cannot be invoked — and what that does not fix
-
Text-to-SQL works beautifully until the schema is real
Why benchmark accuracy does not survive contact with a production database
-
What an agent actually sees when your PL/SQL becomes tools
Records, ref cursors and eight OUT parameters — and why deriving the schema by hand does not scale
-
Oracle ships its own MCP server. When should you use ours instead?
A fair comparison — SQLcl MCP is good at a job that is not the same job
-
LLMs for fun and profit - Why this product exists
What is the product, and why should you trust it?
-
Why can't I just write my own 'safe' SQL MCP interface to Oracle?
Why this is a 'buy' instead of 'build' situation