Shop MCP Server
Shop MCP Server
Локальный MCP-сервер для аналитики SQLite-базы интернет-магазина. AI-агент вызывает MCP-инструмент, сервер преобразует запрос в безопасный SQL SELECT, напрямую читает shop.db и возвращает структурированный результат.
Host-приложение
├── AI-агент / LLM
└── MCP-клиент
│ JSON-RPC / stdio
▼
Shop MCP Server
│ read-only SQLite
▼
data/shop.dbВозможности
прямое подключение к SQLite без HTTP и отдельного DB-сервера;
MCP-транспорт
stdio;обнаружение
query_shopиinspect_databaseчерезtools/list;восемь примеров задания в описании и JSON Schema инструмента;
обычный текст, JSON intent или готовый безопасный
SELECT;исключение заказов
cancelledиз всей аналитики;пагинация и ограничение результата;
многоуровневая read-only защита.
Related MCP server: Read-Only SQLite Shop Database MCP Server
Установка
Требуется Python 3.11 или новее.
python3 -m venv .venv
.venv/bin/python -m pip install -e '.[dev]'Подготовленная база уже находится в data/shop.db. В ней 150 клиентов, поле customers.country заполнено у всех клиентов, а 45 клиентов относятся к Germany.
Повторная подготовка базы
Исходная база не изменяется. Команда создаёт новую рабочую копию и добавляет country TEXT NOT NULL с воспроизводимыми синтетическими значениями:
.venv/bin/shop-prepare-db /path/to/original/shop.db ./data/shop.dbРаспределение зависит только от customers.id, поэтому повторная подготовка даёт те же значения. Страны являются тестовыми данными и не описывают реальное местонахождение клиентов.
Настройка пути
Путь определяется в таком порядке:
SHOP_DB_PATH;JSON-файл из
SHOP_MCP_CONFIGилиconfig/shop_mcp.json;data/shop.dbотносительно рабочей директории.
Пример переменной окружения находится в .env.example, а конфигурация MCP-клиента — в config/mcp.example.json. Замените /absolute/path/to/MCPDeveloper на абсолютный путь к проекту.
Запуск
Обычно сервер запускает MCP-клиент из своей конфигурации. Для ручного запуска процесса:
SHOP_DB_PATH=./data/shop.db .venv/bin/python -m shop_mcp.serverstdout зарезервирован для MCP JSON-RPC. Диагностика не выводится в протокольный поток.
Инструменты
inspect_database
Аргументы:
{"action": "list_tables"}или:
{"action": "describe_table", "table": "customers"}query_shop
Аргументы:
{
"request": "Сколько клиентов из Германии?",
"limit": 100,
"offset": 0
}Примеры, объявляемые через tools/list:
Какие таблицы есть в базе и какие в них поля?
Сколько клиентов из Германии?
В какой стране больше всего клиентов?
Какой клиент потратил больше всего? Верни имя, email и общую сумму.
Покажи топ-5 товаров по проданному количеству и выручке.
Покажи топ-3 категории по выручке.
Какая выручка была в 2025 году?
Какой клиент сделал больше всего заказов?
Можно передать структурированный intent:
{
"request": "{\"intent\": \"revenue_by_year\", \"year\": 2025}"
}Или готовый запрос:
{
"request": "SELECT name, category FROM products ORDER BY name"
}Бизнес-правила
orders.status = 'cancelled'не участвует в метриках.Расходы клиентов и годовая выручка считаются по
orders.total_amount.Выручка товаров и категорий считается как
quantity * unit_price.Интервал года полуоткрытый: от 1 января включительно до 1 января следующего года исключительно.
В поставленной базе все заказы относятся к 2026 году, поэтому выручка за 2025 год равна
0.
Безопасность
Сервер открывает SQLite через mode=ro, включает query_only, устанавливает SQLite authorizer, запрещает несколько выражений, DML, DDL, ATTACH, изменяющие PRAGMA, загрузку расширений и ограничивает время выполнения.
Любая попытка выполнить операцию, отличную от SELECT, возвращает точный ответ:
Не доступный вариант запросаВнутренние ошибки SQLite, stack trace и локальные пути клиенту не возвращаются.
Проверка
.venv/bin/pytest
.venv/bin/ruff check .
.venv/bin/ruff format --check .Тесты включают реальный запуск MCP-сервера как subprocess, подключение ClientSession через stdio, tools/list, вызов обоих инструментов, аналитические сценарии и попытки изменения базы.
Полная утверждённая спецификация находится в docs/specification.md.
Available Tools
2 toolsinspect_databaseПросмотр структуры базы интернет-магазинаB
Возвращает список таблиц или поля выбранной таблицы. Используйте action=list_tables либо action=describe_table.
| Name | Required | Description | Default |
|---|---|---|---|
| table | No | Название таблицы для describe_table | |
| action | Yes | Действие: list_tables или describe_table |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility for behavioral disclosure. It only states that it returns tables or fields, which is basic. It does not disclose any side effects, permission requirements, error behaviors, or what happens when the table does not exist. For a read-only inspection tool this is relatively benign, but the coverage is minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that fully conveys the essential information. It is front-loaded with the primary function and immediately outlines the two actions. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that an output schema exists, the return format is likely covered elsewhere. The description is sufficient for a simple schema-inspection tool, but it lacks any mention of error handling or the distinction from query_shop. It is adequate but not comprehensive.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already provides 100% coverage: 'action' is described as 'list_tables or describe_table' and 'table' as 'table name for describe_table'. The description repeats this mapping without adding new information, so it meets the baseline but does not exceed it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: it returns a list of tables or fields of a selected table. This is a specific verb-resource combination and distinguishes it from the sibling query_shop, which presumably queries data rather than schema. The two modes (list_tables, describe_table) are explicitly mentioned.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides instructions on how to use the tool (choose action) but does not explain when to use this tool versus the sibling query_shop. It offers no context about typical scenarios, prerequisites, or exclusions. The usage guidance is limited to internal action selection, not selection among alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
query_shopЗапрос к базе интернет-магазинаA
Выполняет аналитический запрос к базе интернет-магазина только для чтения. MCP преобразует запрос в безопасный SQL SELECT. Отменённые заказы не учитываются. Примеры: 1) Какие таблицы есть в базе и какие в них поля? 2) Сколько клиентов из Германии? 3) В какой стране больше всего клиентов? 4) Какой клиент потратил больше всего? Верни имя, email и общую сумму. 5) Покажи топ-5 товаров по проданному количеству и выручке. 6) Покажи топ-3 категории по выручке. 7) Какая выручка была в 2025 году? 8) Какой клиент сделал больше всего заказов?
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Максимальное число строк | |
| offset | No | Смещение для пагинации | |
| request | Yes | Аналитический запрос обычным текстом, JSON intent или SQL SELECT. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It explicitly states the tool is read-only, that MCP converts queries into safe SQL SELECT, and that canceled orders are excluded from results. This is useful and goes beyond minimal. It does not mention error handling or response format, but the core behavior is well disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is fairly long because it contains eight examples, but those examples are practical and illustrate valid request formats that are directly relevant to the tool. The purpose statement is front-loaded, and each example adds value, so the length is justified. It is well-structured and not overly verbose.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a natural-language query tool that has an output schema (indicated by the schema signals), the description covers essential context: what the tool does, how it handles queries, and what data is excluded (canceled orders). It could add more about limitations or error behavior, but given the output schema exists and the description is already thorough, it is largely complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% — every parameter has a clear description. The description itself adds little beyond the schema: it repeats the request examples but does not elaborate on limit or offset semantics, which the schema already covers adequately. The baseline of 3 is appropriate because the schema handles the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb and resource: 'performs a read-only analytical query to the online store database' and explains the MCP converts queries to safe SQL SELECT. It is specific about being read-only and analytical, which differentiates it from a generic database tool and gives a clear sense of its function, though it does not explicitly name the sibling tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied through a set of concrete examples that show typical analytical questions (e.g., 'which country has most customers?'). However, the description does not explicitly state when to use this tool versus the sibling 'inspect_database', nor does it provide any exclusions or when-not-to-use guidance. It relies on the reader to infer that this is for read-only analytical queries.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v0.1.0- First observed
inspect_database - First observed
query_shop
TDQS
The two tools have clearly distinct purposes: one handles database schema inspection (list tables/describe fields), the other executes analytical queries. There is no overlap in their functional boundaries, making selection unambiguous for an agent.
Both tools follow a consistent verb_noun snake_case pattern ('inspect_database', 'query_shop'), using clear, descriptive verbs. Naming style is uniform and predictable.
With only 2 tools, the server feels minimal for a shop analytics domain. While the query tool is versatile, a more granular set (e.g., get_customers, get_orders) might be expected. The count is borderline, not excessive but thin.
The tool surface fully covers the stated purpose: schema discovery via inspect_database and arbitrary read-only analytical queries via query_shop. There are no obvious gaps for a read-only analytics server, as the query tool can address any data retrieval need.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Explore, query, and inspect SQLite databases with ease. List tables, preview results, and view det…
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Query 40 databases from Claude, ChatGPT, or Cursor — on any device. Read-only, encrypted, audited.
Commerce intelligence for AI agents. Diagnose drop-offs, fix checkouts, optimize pricing.
Related MCP Servers
- FlicenseAqualityCmaintenanceEnables AI agents to answer analytical questions about an online store's SQLite database through specialized read-only tools, without any risk of modifying the underlying data.8-
- FlicenseAqualityCmaintenanceEnables AI agents to safely inspect and query an SQLite e-commerce database with tools for listing tables, describing schemas, and running read-only SQL queries while blocking destructive operations.4-
- FlicenseAqualityCmaintenanceEnables AI agents to read-only query an online store's SQLite database, listing tables, inspecting schemas, and running SELECT queries over customers, products, orders, and order items.3-
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to read-only analyze a SQLite e-commerce database, exploring schema and running analytical SQL queries over stdio.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/k0ry/MCPDeveloper'
If you have feedback or need assistance with the MCP directory API, please join our Discord server