Skip to content
hs-sql-agent

SQL Server · MCP

Governed AI access to SQL Server.

Connect AI clients to SQL Server through hs-sql-agent's MCP surface, typed SQL compiler, access policy, Safe DML workflow, and audit boundary.

01

One governed MCP surface

Expose SQL Server without handing the model an unrestricted database connection.

02

Dialect-aware compiler

Keep SQL Server-specific SQL semantics inside an explicit source/target capability boundary.

03

Policy before execution

Apply database scope, table policy, tool restrictions, rate limits, Safe DML, and audit before commit.

SQL Server stays behind a compiler boundary

hs-sql-agent does not treat a model-generated SQL Server statement as trusted simply because the provider could execute it. SQL first enters the typed validation and capability pipeline.

Provider support means the runtime can connect, inspect metadata, compile supported statements, and execute them under policy. It does not mean every vendor-specific syntax form is accepted automatically.

Use metadata before guessing schema

MCP clients can discover schemas, tables, and columns through the built-in metadata tools before constructing SQL Server SQL. This reduces blind schema guessing and keeps discovery inside the same authenticated database scope.

  • get_schemas
  • get_tables
  • get_columns
  • execute_query_sql
  • execute_dml_sql

Fail closed when semantics are not proven

The SQL Server path follows the same rule as every other provider: unsupported syntax or cross-provider semantics are rejected at the appropriate validation/capability boundary rather than silently rewritten into a query with different behavior.