Skip to main content

Argos-MCP

A hundred eyes on your databases, and none of them blink.

Argos Panoptes (Ἄργος Πανόπτης) is the giant of Greek myth with a hundred eyes, set by Hera to guard Io. Only some of his eyes slept at a time, so he was never fully asleep and nothing passed him unseen. Panoptes means 'all-seeing'.

What it does

Argos-MCP connects Claude Code, or any other MCP client, to PostgreSQL, MySQL/MariaDB, SQLite, and SQL Server. It sits in front of the connection, not beside it: every query passes SELECT-only validation (bound parameters, no stacked statements, complexity limits) before it reaches the driver, and every query produces exactly one audit record: database, statement hash, duration, and outcome, never the values themselves.

You can configure multiple databases at once, over SSH tunnels with a pinned host key fingerprint, with field redaction so sensitive columns (emails, phone numbers, SSNs) never reach the model, and with a one-way lock (mcp_configurable) that shuts a database off from further changes through MCP once its settings are where you want them.

Quick start

Argos-MCP is not yet published to npm, so install it from source. Requires Node.js 22 or newer and the Claude Code CLI.

bash
git clone https://github.com/AraneaDev/Argos-MCP.git
cd Argos-MCP
npm install
npm run build
npm run setup
claude mcp add argos --scope user -- \
  node "$(pwd)/dist/index.js" --config "$HOME/.config/argos/config.ini"

npm run setup runs an interactive wizard for database connections, security settings, and SSH tunnels, and writes them to config.ini.

Examples

An sql_query call, run for real against a local SQLite database:

Call:

json
{
  "database": "demo",
  "query": "SELECT id, name, email FROM users ORDER BY id"
}

Result:

text
 Query executed successfully on demo
 SELECT-only mode active
 Results: 3 rows

| id | name | email |
|---|---|---|
| 1 | Ada Lovelace | ada@example.com |
| 2 | Alan Turing | alan@example.com |
| 3 | Grace Hopper | grace@example.com |

Capabilities

CategoryWhat it provides
SecuritySELECT-only mode, query validation against SQL injection, complexity limits, SSH tunneling with pinned host keys, field redaction
DatabasesPostgreSQL, MySQL/MariaDB, SQLite, SQL Server, each with its own adapter
Managementsql_add_database, sql_update_database, sql_remove_database, sql_get_config (passwords always redacted), sql_set_mcp_configurable
PerformanceConnection pooling, per-session schema caching, sql_analyze_performance with dialect-specific advice, sql_get_metrics (min/max/avg/p95)

Databases added at runtime through sql_add_database are always select_only: true; granting write access requires editing config.ini by hand, so the model cannot grant it to itself.

Configuration

Argos-MCP reads config.ini, by default from ~/.config/argos/config.ini; npm run setup writes one for you. This is what a production database behind an SSH tunnel looks like:

ini
[database.production]
type=postgresql
host=internal-db.company.local
port=5432
database=production_app
username=readonly_user
password=secure_random_password
ssl=true
select_only=true

ssh_host=bastion.company.com
ssh_port=22
ssh_username=tunnel_user
ssh_private_key=/secure/path/ssh_key
ssh_host_fingerprint=SHA256:47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU

[security]
max_joins=5
max_subqueries=3
max_complexity_score=50

Without a pinned ssh_host_fingerprint the tunnel refuses to connect, rather than trusting whatever host key it is offered. select_only is the production default; turn it off only on a database where write access is deliberately wanted.