MCPDBWizard

Writing  · 

Why can't I just write my own 'safe' SQL MCP interface to Oracle?

There are a whole series of reasons. For a small, personal implementation it will probably be OK. But as you scale things will rapidly go wrong.

If what you are really after is a way to restrict what an MCP server can do, that is a separate question with six possible answers, and it is worth knowing which of them hold.

A non-deterministic tool can’t be proven safe…

The biggest single issue is this: Your compliance department wants to be 100% sure that none of your LLMs will get up to funny business. But the problem is that LLMs are non-deterministic, and will happily pass testing and then start engaging in novel behaviours because they feel like it.

No pure LLM solution that has access to a SQL prompt can be 100% trusted. Period.

Is this a good use of your tokens?

We are currently at peak TokenMaxxing. This will not last forever, and at some point developers will have to justify token usage. Burning tokens on a hard task (like this one!) when there is a perfectly viable solution avaible will make about as much sense as writing your own web browser.

There’s an awful lot of work involved.

90% of the product code dates back to when it was originally written in 2002-2003. It’s around 3.3 million lines. Now, granted, this is code generation, so line counts can be high, but that’s still a lot of work.

We tried it. It didn’t go so well.

Before we started this reboot we tried to replicate the functionality by asking Claude to write code. Once you get beyond the complexity of an average Stackoverflow question things .. well .. fell apart…

How do I get MCP DB Wizard?

Currently it’s available via our GitHub Repo as a docker image.