{"name":"sh.valv/mcp","slug":"valv-mcp","title":"valv","description":"Let coding agents query any SQL database safely. Read-only by default and scoped by your policies.","url":"https://mcp.market/server/valv-mcp","rating":null,"grade":"B","score":80,"certified":false,"status":"active","category":"data","tags":["data"],"presence":{"score":33,"stars":5,"forks":0,"downloads_week":30,"last_push_at":"2026-09-11T10:05:11.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/valv-dev/valv","website":"https://valv.sh","version":"0.6.2","remotes":[],"packages":[{"registryType":"npm","identifier":"@valv/mcp","version":"0.6.2","transport":{"type":"stdio"},"environmentVariables":[{"description":"Database connection string. PostgreSQL, MySQL, SQLite, CockroachDB, or a ClickHouse HTTP URL.","isRequired":true,"format":"string","isSecret":true,"name":"DATABASE_URL"},{"description":"Datasource provider: postgresql, mysql, sqlite, or clickhouse. Inferred from DATABASE_URL when omitted.","format":"string","choices":["postgresql","mysql","sqlite","clickhouse"],"name":"VALV_PROVIDER"},{"description":"Database name. Required for ClickHouse, whose URL does not carry one.","format":"string","name":"VALV_DATABASE"},{"description":"Comma-separated allow-list of tables. When set, only these are exposed to the agent.","format":"string","name":"VALV_TABLES"},{"description":"Comma-separated deny-list of tables, applied after the allow-list.","format":"string","name":"VALV_EXCLUDE"},{"description":"Path to a policy module that takes full control of access. Without it, the server is read-only across all tables.","format":"filepath","name":"VALV_POLICY_FILE"},{"description":"JSON context object the policy reads, e.g. {\"tenant\":{\"id\":\"acme\"}}.","format":"string","name":"VALV_CONTEXT"},{"description":"Serve over Streamable HTTP on this port instead of stdio.","format":"number","name":"VALV_HTTP_PORT"}]}],"tools":[],"scan":{"score":80,"grade":"B","scanned_at":"2026-09-24T17:27:40.599Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-24T17:27:40.505Z","components":{"code":{"score":25,"max":25,"notes":["11 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 13 days ago"]},"identity":{"score":6,"max":10,"notes":["namespace and repository owner differ","website matches verified namespace"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@valv/mcp","version":"0.6.2","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":8,"publishedAt":"2026-07-28T08:13:46.615Z","repositoryUrl":"git+https://github.com/valv-dev/valv.git","weeklyDownloads":30}],"repo":{"found":true,"owner":"valv-dev","repo":"valv","archived":false,"pushedAt":"2026-09-11T10:05:11Z","stars":5,"forks":0,"openIssues":0,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/289263654?v=4","ownerCreatedAt":"2026-05-30T18:49:35Z","license":"MIT"},"icon":{"url":"https://valv.sh/favicon.svg","source":"site"},"presence":{"stars":5,"forks":0,"downloadsWeek":30,"license":"MIT","lastPushAt":"2026-09-11T10:05:11.000Z","score":33}}}},"grade_history":[],"reviews":[]}