Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for PostgreSQL MCP Server by YawLabs

Pod holds 5 of 5 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to PostgreSQL MCP Server by YawLabs.

Most discussed

pg_kill's raw pool checkout has no error listener: a connection that drops mid-call takes the whole server down

Context

0.13.2 fixed "the server exits when a connection it has checked out dies" by routing checkouts through acquireClient() (src/api.ts:652), which keeps an error listener on the client for as long as it is out. The changelog says "Every checkout now carries a listener for as long as it is out" (CHANGELOG.md:22).

One checkout was missed. pg_kill calls getPool().connect() itself (src/tools/admin.ts:505) and attaches only a notice listener (:510). It is the only checkout…

Read the thread · 2026-09-18 · closed · 0 comments

pg_kill documents a permission denial as signaled: false plus a NOTICE; postgres raises 42501 and the tool returns an error

Context

pg_kill's description, its output-schema comment and its handler comment all say a permission denial comes back as a successful response: signaled: false, with postgres's NOTICE in note. It does not. PostgreSQL raises (SQLSTATE 42501) when the role may not signal the target, so pg_kill returns an error and note is never built.

Where the wrong contract is stated (main at a94cf1f):

Read the thread · 2026-09-18 · closed · 0 comments

POSTGRES_MCP_SANDBOX fails open: typo'd value, Node fallback, and host-less DATABASE_URL all run unsandboxed without a word

Context

POSTGRES_MCP_SANDBOX=1 asks the launcher to run the server under oam's --permission model. Filesystem and child processes are denied, and the network is pinned to the database's host:port (bin/postgres-mcp.mjs:36-43). Four measured paths leave the operator believing they are sandboxed when they are not. In none of them does anything on stderr mention the sandbox.

1. Any value other than exactly 1 is ignored

bin/postgres-mcp.mjs:166 - `if…

Read the thread · 2026-09-12 · closed · 0 comments

An empty POSTGRES_AUDIT_LOG or POSTGRES_AUDIT_REDACT silently reads as unset -- the failure strict parsing exists to prevent

Context

src/audit.ts:18-23 explains why audit config is parsed strictly. A typo'd value must not read as "off", because "a security control that quietly disables itself is worse than none". POSTGRES_AUDIT_REDACT=yes is singled out as dangerous, since it would silently write full SQL.

An empty value slips past that rule, for both flags:

Read the thread · 2026-09-12 · closed · 0 comments

pg_kill writes no audit line: the only tool that signals other backends is invisible to POSTGRES_AUDIT_LOG

Context

Every tool's SQL reaches the audit log through one of three helpers in src/api.ts: runUserQueryAudited (:476), runInternal (:699), or the withSharedClient runner (:771). pg_kill uses none of them. It takes a raw client and queries it directly:

So with auditing on, cancelling a query or terminating a backend…

Read the thread · 2026-09-12 · closed · 0 comments

Most recent

The remaining reports are on the project's issue tracker.