Skip to main content
Glama
k0ry

Shop MCP Server

by k0ry

Shop MCP Server

Local MCP server for analytics of an online store's SQLite database. The AI agent calls an MCP tool, the server converts the request into a safe SQL SELECT, directly reads shop.db, and returns a structured result.

Host-приложение
├── AI-агент / LLM
└── MCP-клиент
        │ JSON-RPC / stdio
        ▼
    Shop MCP Server
        │ read-only SQLite
        ▼
    data/shop.db

Features

  • direct SQLite connection without HTTP or a separate DB server;

  • MCP stdio transport;

  • query_shop and inspect_database discovery via tools/list;

  • eight example tasks in the description and JSON Schema of the tool;

  • plain text, JSON intent, or a ready-made safe SELECT;

  • exclusion of cancelled orders from all analytics;

  • pagination and result limiting;

  • multi-level read-only protection.

Related MCP server: Read-Only SQLite Shop Database MCP Server

Installation

Requires Python 3.11 or newer.

python3 -m venv .venv
.venv/bin/python -m pip install -e '.[dev]'

The prepared database is already located in data/shop.db. It contains 150 customers, the customers.country field is filled in for all customers, and 45 customers belong to Germany.

Re-preparing the database

The source database is not modified. The command creates a new working copy and adds country TEXT NOT NULL with reproducible synthetic values:

.venv/bin/shop-prepare-db /path/to/original/shop.db ./data/shop.db

The distribution depends only on customers.id, so re-preparation yields the same values. The countries are test data and do not describe the actual location of customers.

Path configuration

The path is determined in the following order:

  1. SHOP_DB_PATH;

  2. JSON file from SHOP_MCP_CONFIG or config/shop_mcp.json;

  3. data/shop.db relative to the working directory.

An example environment variable is in .env.example, and the MCP client configuration is in config/mcp.example.json. Replace /absolute/path/to/MCPDeveloper with the absolute path to the project.

Running

Usually the MCP client starts the server from its own configuration. To run the process manually:

SHOP_DB_PATH=./data/shop.db .venv/bin/python -m shop_mcp.server

stdout is reserved for MCP JSON-RPC. Diagnostics are not output to the protocol stream.

Tools

inspect_database

Arguments:

{"action": "list_tables"}

or:

{"action": "describe_table", "table": "customers"}

query_shop

Arguments:

{
  "request": "Сколько клиентов из Германии?",
  "limit": 100,
  "offset": 0
}

Examples declared via tools/list:

  1. What tables are in the database and what fields do they have?

  2. How many customers are from Germany?

  3. Which country has the most customers?

  4. Which customer spent the most? Return the name, email, and total amount.

  5. Show the top 5 products by quantity sold and revenue.

  6. Show the top 3 categories by revenue.

  7. What was the revenue in 2025?

  8. Which customer placed the most orders?

You can pass a structured intent:

{
  "request": "{\"intent\": \"revenue_by_year\", \"year\": 2025}"
}

Or a ready-made query:

{
  "request": "SELECT name, category FROM products ORDER BY name"
}

Business rules

  • orders.status = 'cancelled' does not participate in metrics.

  • Customer spending and annual revenue are calculated from orders.total_amount.

  • Product and category revenue is calculated as quantity * unit_price.

  • The year interval is half-open: from January 1 inclusive to January 1 of the next year exclusive.

  • In the provided database, all orders belong to 2026, so revenue for 2025 is 0.

Security

The server opens SQLite via mode=ro, enables query_only, sets up a SQLite authorizer, forbids multiple statements, DML, DDL, ATTACH, modifying PRAGMA, extension loading, and limits execution time.

Any attempt to perform an operation other than SELECT returns a precise answer:

Не доступный вариант запроса

Internal SQLite errors, stack traces, and local paths are not returned to the client.

Testing

.venv/bin/pytest
.venv/bin/ruff check .
.venv/bin/ruff format --check .

The tests include a real MCP server launch as a subprocess, a ClientSession connection via stdio, tools/list, calls to both tools, analytical scenarios, and attempts to modify the database.

The full approved specification is in docs/specification.md.

Available Tools

2 tools
inspect_databaseПросмотр структуры базы интернет-магазинаB

Возвращает список таблиц или поля выбранной таблицы. Используйте action=list_tables либо action=describe_table.

ParametersJSON Schema
NameRequiredDescriptionDefault
tableNoНазвание таблицы для describe_table
actionYesДействие: list_tables или describe_table

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full responsibility for behavioral disclosure. It only states that it returns tables or fields, which is basic. It does not disclose any side effects, permission requirements, error behaviors, or what happens when the table does not exist. For a read-only inspection tool this is relatively benign, but the coverage is minimal.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence that fully conveys the essential information. It is front-loaded with the primary function and immediately outlines the two actions. No redundancy or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given that an output schema exists, the return format is likely covered elsewhere. The description is sufficient for a simple schema-inspection tool, but it lacks any mention of error handling or the distinction from query_shop. It is adequate but not comprehensive.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already provides 100% coverage: 'action' is described as 'list_tables or describe_table' and 'table' as 'table name for describe_table'. The description repeats this mapping without adding new information, so it meets the baseline but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: it returns a list of tables or fields of a selected table. This is a specific verb-resource combination and distinguishes it from the sibling query_shop, which presumably queries data rather than schema. The two modes (list_tables, describe_table) are explicitly mentioned.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides instructions on how to use the tool (choose action) but does not explain when to use this tool versus the sibling query_shop. It offers no context about typical scenarios, prerequisites, or exclusions. The usage guidance is limited to internal action selection, not selection among alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

query_shopЗапрос к базе интернет-магазинаA

Выполняет аналитический запрос к базе интернет-магазина только для чтения. MCP преобразует запрос в безопасный SQL SELECT. Отменённые заказы не учитываются. Примеры: 1) Какие таблицы есть в базе и какие в них поля? 2) Сколько клиентов из Германии? 3) В какой стране больше всего клиентов? 4) Какой клиент потратил больше всего? Верни имя, email и общую сумму. 5) Покажи топ-5 товаров по проданному количеству и выручке. 6) Покажи топ-3 категории по выручке. 7) Какая выручка была в 2025 году? 8) Какой клиент сделал больше всего заказов?

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoМаксимальное число строк
offsetNoСмещение для пагинации
requestYesАналитический запрос обычным текстом, JSON intent или SQL SELECT.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It explicitly states the tool is read-only, that MCP converts queries into safe SQL SELECT, and that canceled orders are excluded from results. This is useful and goes beyond minimal. It does not mention error handling or response format, but the core behavior is well disclosed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is fairly long because it contains eight examples, but those examples are practical and illustrate valid request formats that are directly relevant to the tool. The purpose statement is front-loaded, and each example adds value, so the length is justified. It is well-structured and not overly verbose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a natural-language query tool that has an output schema (indicated by the schema signals), the description covers essential context: what the tool does, how it handles queries, and what data is excluded (canceled orders). It could add more about limitations or error behavior, but given the output schema exists and the description is already thorough, it is largely complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% — every parameter has a clear description. The description itself adds little beyond the schema: it repeats the request examples but does not elaborate on limit or offset semantics, which the schema already covers adequately. The baseline of 3 is appropriate because the schema handles the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb and resource: 'performs a read-only analytical query to the online store database' and explains the MCP converts queries to safe SQL SELECT. It is specific about being read-only and analytical, which differentiates it from a generic database tool and gives a clear sense of its function, though it does not explicitly name the sibling tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied through a set of concrete examples that show typical analytical questions (e.g., 'which country has most customers?'). However, the description does not explicitly state when to use this tool versus the sibling 'inspect_database', nor does it provide any exclusions or when-not-to-use guidance. It relies on the reader to infer that this is for read-only analytical queries.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 2 tool updatesv0.1.0
    • First observedinspect_database
    • First observedquery_shop

TDQS

A3.8/5.0
Disambiguation5/5

The two tools have clearly distinct purposes: one handles database schema inspection (list tables/describe fields), the other executes analytical queries. There is no overlap in their functional boundaries, making selection unambiguous for an agent.

Naming Consistency5/5

Both tools follow a consistent verb_noun snake_case pattern ('inspect_database', 'query_shop'), using clear, descriptive verbs. Naming style is uniform and predictable.

Tool Count3/5

With only 2 tools, the server feels minimal for a shop analytics domain. While the query tool is versatile, a more granular set (e.g., get_customers, get_orders) might be expected. The count is borderline, not excessive but thin.

Completeness5/5

The tool surface fully covers the stated purpose: schema discovery via inspect_database and arbitrary read-only analytical queries via query_shop. There are no obvious gaps for a read-only analytics server, as the query tool can address any data retrieval need.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • F
    license
    A
    quality
    C
    maintenance
    Enables AI agents to answer analytical questions about an online store's SQLite database through specialized read-only tools, without any risk of modifying the underlying data.
    8
    -
  • F
    license
    A
    quality
    C
    maintenance
    Enables AI agents to safely inspect and query an SQLite e-commerce database with tools for listing tables, describing schemas, and running read-only SQL queries while blocking destructive operations.
    4
    -
  • F
    license
    A
    quality
    C
    maintenance
    Enables AI agents to read-only query an online store's SQLite database, listing tables, inspecting schemas, and running SELECT queries over customers, products, orders, and order items.
    3
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to read-only analyze a SQLite e-commerce database, exploring schema and running analytical SQL queries over stdio.
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/k0ry/MCPDeveloper'

If you have feedback or need assistance with the MCP directory API, please join our Discord server