| FMRS | 59 / 100 · C | 79 / 100 · B | 74 / 100 · B |
| Reliability | 8 / 20 | 12 / 20 | 13 / 20 |
|---|
| Security and permissions | 12 / 20 | 18 / 20 | 13 / 20 |
|---|
| Maintenance | 13 / 20 | 17 / 20 | 17 / 20 |
|---|
| Documentation | 12 / 20 | 17 / 20 | 16 / 20 |
|---|
| Setup experience | 14 / 20 | 15 / 20 | 15 / 20 |
| Best for | - Security analysts conducting threat hunting in Elasticsearch or OpenSearch environments
- Incident responders needing AI-assisted investigation workflows
- Red teams/security testers analyzing attack simulation data
- Researchers using cyber range environments like crowdsentinel-range
| - Teams already using ClickHouse who want AI assistants to access data directly.
- Scenarios requiring fast, read-only data queries and schema exploration.
| - Teams that want precise control over which database operations an AI can perform, rather than open arbitrary SQL execution
- Scenarios needing a unified MCP setup across multiple database engines
|
| Not for | - Production environments (explicitly warned not for production)
- Users without security background (targets DFIR professionals)
- Users needing Splunk integration (still on roadmap)
- Users relying on a single data source (integrates with multiple)
| - Scenarios requiring write access to the database without explicit opt-in.
- Production environments with stringent security requirements that avoid default permission settings.
| - Lightweight cases that just want to run a few ad-hoc SQL queries without maintaining a tools.yaml config (a simpler single-database MCP may be a better fit)
|
| Required permissions | - Requires Elasticsearch/OpenSearch credentials (API key or username/password)
- Can read and write Elasticsearch indices (can be restricted via DISABLE_HIGH_RISK_OPERATIONS)
- Optional API keys for external threat intelligence services (VirusTotal, Shodan, etc.)
- Requires local system permissions to run tools like osquery and tshark
- Requires Velociraptor API configuration for endpoint forensics
| - Requires read-only access to ClickHouse database (default).
- Optional: write access via CLICKHOUSE_ALLOW_WRITE_ACCESS.
- Optional: destructive operations via CLICKHOUSE_ALLOW_DROP.
| - Database credentials (username/password/connection string) are supplied via env vars or config
- A tool's actual permission is whatever SQL statement is defined in tools.yaml — designed for least privilege, but misconfiguration can still over-expose access
|
| Risks and side effects | - High-risk operations: can create/delete indices, documents, data streams, and aliases
- Potential sensitive data exposure: searches may return documents containing PII or sensitive security data
- TLS verification disabled by default (VERIFY_CERTS default false), risk of man-in-the-middle attacks
- External service dependencies: requires access to threat intelligence APIs, may incur costs or rate limits
- Active development status: APIs may change, not suitable for production
| - If write access is enabled, AI might make unintended modifications.
- If DROP access is enabled, data deletion could occur accidentally.
- Credentials may be exposed via environment variables.
| - If tools.yaml defines SQL statements that allow unconstrained writes or deletes, the AI could accidentally modify data
- The prebuilt toolsets (--prebuilt) favor convenience and may expose broader query capability than a specific business actually needs — use a custom tools.yaml in production
|
| Supported clients | Claude Code, Claude Desktop, VS Code Copilot, Cursor, Roo Code, 5ire | Claude Desktop | Claude Code, Gemini CLI, Zed, Antigravity |
| Tools | 0 | 4 | 0 |