scanned 1mo ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
ClickHouse MCP Server
mcp-clickhouse is an official Model Context Protocol server that connects ClickHouse, the high-performance OLAP database, to AI assistants.
It exposes tools including run_query to execute SQL (read-only by default, with writes gated behind an explicit flag), list_databases to enumerate databases, and list_tables to browse tables with pagination. This lets an agent explore schemas and run analytical queries against a ClickHouse cluster safely.
It is aimed at analysts and engineers who want natural-language, read-safe access to ClickHouse analytics data.
! Security: Review · 7575/100 · grade Bscanned 1mo ago
✓ no compromise signals9 risk-surface · 5/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · med confidence (static)
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM03Supply Chaincritical
Vulnerable/compromised dependencies, models or archives in the artifact.