1 comments

  • depthfirst an hour ago

    HI HN, this is Vivek (from Contextflo). We help companies connect their AI agents to company data.

    Our "connect Claude to Postgres" guide was recommending the official @modelcontextprotocol/server-postgres. It turned out to be archived with a known hole: it ran each query in a read-only transaction but accepted several statements at once, so COMMIT; DROP SCHEMA public CASCADE got through.

    So we wrote a replacement. Two things are different: - Read-only is enforced in several places: the wire protocol rejects multiple statements, the transaction is read-only, the real Postgres parser checks every statement, and functions Postgres marks as having side effects are blocked. That last check came from asking Claude to break our own guards. It found pg_logical_emit_message, which writes to the WAL inside a read-only transaction. - A context file in your repo, seeded from your COMMENT ON descriptions. The agent can append what it learns ("amount is in cents", "this table only has completed orders"), so the next session starts with it. The reason to integrate context file inside the mcp connector was to have more fine control of what the agent sees (compared to agent managing its own md file). You can swap out agents any time with just mcp connection.

    Would love any feedbacks on this.