Security audit
MySQL MCP Guard
Security checks for vulnerabilities and agentic risk
Overview
This plugin does what it claims: it registers guarded MySQL tools that use configured credentials and the local mysql client, with read-only behavior by default.
Install only for databases you intend the agent to access. Use a read-only MySQL user by default, keep allowWrite=false unless you are on a controlled database, set defaultLimit/maxLimit/maxOutputChars for large tables, and avoid exposing broad production credentials through environment variables.
Static analysis
No suspicious patterns detected.
