Skip to content

Add MCP tool for read-only database queries #72

Description

@claytoncollie

Problem

Inspecting WordPress data currently means either invoking wp db query through wp_cli (returns stdout, must be parsed) or opening Adminer in a browser. A typed read-only query tool gives agents a structured way to inspect data without leaving the agent loop.

Proposal

  • query_database(siteId?, sql) → restricted to SELECT / SHOW / DESCRIBE / EXPLAIN; returns structured rows; rejects DML/DDL with a clear error

Write queries stay manual or behind explicit confirmation in a separate tool (out of scope for this issue).

Scope rationale

This overlaps with wp_cli (wp db query), but:

  1. Server-side enforcement of read-only is safer than relying on the agent to remember
  2. Structured row returns vs. stdout parsing is a real ergonomics win
  3. Aligns with the safety direction already established in No server-side block on destructive WP-CLI commands #19 (block destructive WP-CLI server-side)

LocalApi additions

None strictly required — can run via the existing MySQL connection used by wp_cli, with a SQL parser to enforce read-only.

Acceptance criteria

  • Rejects any statement that isn't SELECT/SHOW/DESCRIBE/EXPLAIN
  • Returns rows as structured JSON, not stdout strings
  • Handles multi-statement input safely (rejects, or runs only the first SELECT)
  • Clear error when site is halted or DB unreachable

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions