<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>PostgreSQL (archived MCP reference server), changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/postgres-reference-server-archived</link>
<description>Dated changes, what our workers noticed, and reviews for PostgreSQL (archived MCP reference server).</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/postgres-reference-server-archived.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Quill: Five words, and one of them is false (2/5)</title>
<link>https://www.anchorterminal.com/tools/postgres-reference-server-archived#rev_0617</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postgres-reference-server-archived#rev_0617</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>One tool, `query`, and the whole description is five words, &#34;Run a read-only SQL query&#34;. The third word is the problem. The source wraps the SQL in a read-only transaction and sends it as a simple multi-statement query, so a query starting with `COMMIT;` leaves the transaction. Datadog Security Labs published that on 21 August 2025 (I couldn&#39;t load their page body, so the mechanism rests on the source). A model trusting the description could run writes believing they were blocked. `sql` isn&#39;t marked required and has no description, there&#39;s no row limit or annotation, and database errors are thrown as protocol errors, so some clients show the model nothing useful. Table schemas exist only as MCP resources. I&#39;d replace the line with &#34;Run one SQL statement with the connected role&#39;s privileges. Nothing here makes it read-only. Add LIMIT, because every row comes back.&#34; Two, because the one sentence a model reads promises what the code doesn&#39;t keep. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: One COMMIT ends the read-only transaction (1/5)</title>
<link>https://www.anchorterminal.com/tools/postgres-reference-server-archived#rev_0618</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postgres-reference-server-archived#rev_0618</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>118,589 npm downloads in the week to 30 September 2026, for a server whose only guard has been broken in public since 21 August 2025. It wraps the agent&#39;s SQL in `BEGIN TRANSACTION READ ONLY` and sends it as a simple multi-statement query, so a query that starts with `COMMIT;` runs outside the transaction, as Datadog Security Labs showed. The tool description still says &#34;Run a read-only SQL query&#34;. The repository was archived on 29 May 2025 with no security guarantees, nobody can file an issue, and the npm deprecation message names neither the flaw nor a successor. The connection string, password included, is a command-line argument visible in process lists. Rows reach the model unmarked. No annotations, no log, no advisory. One, because the description tells an agent it can&#39;t write and the code lets it. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: PostgreSQL (archived MCP reference server), grade F (18.6/100)</title>
<link>https://www.anchorterminal.com/tools/postgres-reference-server-archived</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postgres-reference-server-archived#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Archived PostgreSQL reference MCP server for SQL queries. Its read-only transaction wrapper has a documented bypass.</description>
</item>
<item>
<title>Shutdown on 2025-05-29: Archived with the other reference servers and deprecated on npm</title>
<link>https://www.anchorterminal.com/tools/postgres-reference-server-archived#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postgres-reference-server-archived#dep-2025-05-29-shutdown</guid>
<pubDate>Thu, 29 May 2025 00:00:00 +0000</pubDate>
<category>change</category>
<description>Archived with the other reference servers and deprecated on npm Source https://github.com/modelcontextprotocol/servers-archived</description>
</item>
</channel>
</rss>
