CockroachDB MCP — security audit

CockroachDB MCP: trust score 64/100 — 1 capability surface.

Trust score

64

Grade C

Risk flags

  • No public repository linked

    Without a public repo we cannot independently audit the code. Caution warranted.

Capability surface

  • Database mutation

    Medium risk

    Connects to a database. Read-only flag, when present, mitigates the risk.

    Evidence: postgres

Trust signals

Total trust score is the sum of these contributions. Each signal carries a fixed weight.

  • Verified by Loadout

    +20 / 20

    Manually verified.

  • Official author

    +15 / 15

    Maintained by the official Cockroach Labs team.

  • Community traction

    +14 / 20

    720 GitHub stars.

  • Public source

    +0 / 15

    No linked public repository.

  • Stability

    +0 / 15

    Stability not yet assessed.

  • Capability surface

    +15 / 15

    No high-risk capabilities detected.

Disclaimer

This is an automated heuristic triage. It does not replace a hand-rolled code audit. Use it to prioritise which servers deserve a deeper look — especially anything carrying high-risk capabilities like shell execution or filesystem write.