SQLite (archived)
Archived official reference server for SQLite database queries and analysis. Moved to modelcontextprotocol/servers-archived and no longer actively maintained.
Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.
Low transparency: this server declares few or no tool behavior annotations, so the danger score is inferred from defaults. Treat as cannot verify safe — not necessarily dangerous.
Grade history
12 scans on record between 2026-06-28 and 2026-07-04. The grade has not changed across them.
| Scanned (UTC) | Grade | Engine | Attributed cause |
|---|---|---|---|
| 2026-06-28 03:21 | F | mcpaudit 2.1.0 | First scan on record |
| 2026-06-28 03:37 | F | mcpaudit 2.1.0 | No change |
| 2026-07-03 02:50 | F | mcpaudit 2.1.0 | No change |
| 2026-07-03 09:44 | F | mcpaudit 2.3.0 | Scanner engine changed |
| 2026-07-03 10:00 | F | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:01 | F | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:12 | F | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:16 | F | mcpaudit 2.3.0 | No change |
| 2026-07-03 12:42 | F | mcpaudit 2.3.0 | No change |
| 2026-07-03 13:21 | F | mcpaudit 2.4.0 | No change |
| 2026-07-03 14:13 | F | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:18 | F | mcpaudit 2.4.0 | No change |
History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.
How to read this grade
- What was scanned: mcp-server-sqlite, as distributed.
- When: 2026-07-04 08:18:07.
- By what: mcpaudit 2.4.0, applied to the published danger rubric (weights, bands, and the critical cap are all public).
- What the grade means: this registry's opinion, computed by the disclosed automated methodology against the artifact version above, on the scan date above. It measures conformance to the rubric at scan time.
- What it does not claim: it is not a statement that the product is malicious, insecure in your deployment, or unfit for use, and it is not an endorsement or certification.
- Because this server declares few or no tool-behavior annotations, its F reflects risk inferred from spec defaults — read it as cannot verify safe, not known dangerous.
- Disagree? Grades are re-checkable against the same package version, and corrections are welcome: open a dispute — see the dispute & correction policy.
Spec-shift exposure
BREAKS against MCP 2026-07-28-rc · confidence high · ruled 2026-07-18
| Dimension | Area | Verdict |
|---|---|---|
| D1 | Stateless-core compatibility | BREAKS |
| D2 | Deprecated-capability reliance | READY |
| D3 | Authorization posture | N_A |
| D4 | Schema and wire conformance | READY |
| D5 | Extensions readiness | NOTE |
What to change
- D1 [upstream-blocked] Pass stateless=True to server.run() at src/mcp_server_sqlite/server.py:373, alongside a floor bump to an SDK release that exposes the parameter. The server holds no per-connection state that depends on the handshake, so the change is behavior-preserving. Effort is upstream-blocked, not trivial: modelcontextprotocol/servers-archived is unmaintained by policy and mcp-server-sqlite has not published since 2025-04-25, so no maintainer exists to land it - a consumer would have to fork or vendor.
This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.
Provenance & dispute
- Listing basis: operator-listed from a public catalog. This entry was not submitted by its vendor.
- Scan target: the published pypi artifact
mcp-server-sqlite, installed and scanned locally using sandbox imagemcp-trust-scan:corpus-2026-07-03. The public record stores the sandbox image, but not the network mode, so this page does not claim network isolation for that run. - Credentials: none declared, none used.
- Dispute: vendor or maintainer of this server? Dispute this grade — first response within 14 days.
Add this badge to your README
Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:
[](https://mcp-trust.vercel.app/ui/servers/mcp-archived-sqlite)
Findings
| Severity | Rule | Title | Category | Detail |
|---|---|---|---|---|
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | read; query |
| medium | MCP004 | Shell execution capability | shell_execution | execute |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | query |
| high | MCP002 | File write capability | file_write | write; delete; update |
| medium | MCP004 | Shell execution capability | shell_execution | execute |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | query |
| medium | MCP002 | File write capability | file_write | create |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| medium | MCP001 | File read capability | file_read | list |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| medium | MCP001 | File read capability | file_read | describe |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP002 | File write capability | file_write | append; add |
Score breakdown
| Dimension | Raw (0–10) | Weight | Weighted |
|---|---|---|---|
| File access | 1.8 | ×1.2 | 2.16 |
| Network access | 1.5 | ×1.0 | 1.50 |
| Shell execution | 1.8 | ×2.0 | 3.60 |
| Destructive | 2.0 | ×0.3 | 0.60 |
| Exfiltration | 0.0 | ×0.4 | 0.00 |