db-mcp (SQLite MCP Server)
Secure Database MCP Server featuring a V8 Isolate Code Mode sandbox that unifies 181+ tools, delivering 70-90% token sav
Compare db-mcp (SQLite MCP Server)
How does it stack up against its MCP Servers neighbours?
Pick any agent to compare →Thin or incomplete trust evidence. Review carefully before production use.
Is db-mcp (SQLite MCP Server) safe? db-mcp (SQLite MCP Server) scores 37.8/100 (Grade D), ranked #659 of 1283 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types). The public evidence: its packages ship with cryptographic provenance; no OSSF Scorecard result yet; 34% of recent commits are signed; last pushed 2026-08-04. Every point is earned from checkable signals — never paid placement. How scoring works →
Ranked neighbours in MCP Servers
Quick Trust Read
How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade D reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →
Rank Trend
Activity & Reach
Analysis
HVTrust Dimensions vs MCP Servers
37.8 / 100 · 67.0% confidencedb-mcp (SQLite MCP Server) MCP Servers average (761 agents)
Activity Inputs
31.5 / 100Supply Chain Trust
Is db-mcp (SQLite MCP Server) safe?
Does db-mcp (SQLite MCP Server) publish package provenance?
Does db-mcp (SQLite MCP Server) have an OpenSSF Scorecard?
Is db-mcp (SQLite MCP Server) actively maintained?
What license does db-mcp (SQLite MCP Server) use?
Are db-mcp (SQLite MCP Server)'s commits signed?
Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.
AI agent surface
MCP, providers, tool surface
These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →
- database
- MCP signal live
- External deps live
- Tool / plugin surface live
- Package provenance drift live
Maintain db-mcp (SQLite MCP Server)?
For maintainers
HVTrust scores db-mcp (SQLite MCP Server) from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.
Reputation Timeline
Signal history
Embed Badge Badge guide for maintainers →
For maintainers
[](https://hvtracker.net/agents/db-mcp-sqlite-mcp-server)
<a href="https://hvtracker.net/agents/db-mcp-sqlite-mcp-server"><img src="https://hvtracker.net/badge/db-mcp-sqlite-mcp-server.svg" alt="HVTrust"></a>
Other agents in MCP Servers
GitHub REST API (repo, commits, stars, forks, license) · npm Registry (downloads, provenance)
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON