vektor-guard
v0.3.1
Published
Stop your AI agent from running DROP TABLE on production. Decides on PostgreSQL's own parse tree, not patterns. MCP server for Claude Desktop and Cursor, plus a CLI.
Maintainers
Readme
vektor-guard
Stop your AI agent from running DROP TABLE on production.
Works inside Claude Desktop, Cursor, or wherever you already work — no new app to learn.
Why this exists
In July 2026 a developer gave an AI agent write access to a production Supabase instance. A single prisma migrate diff — with --shadow-database-url resolving to the production connection — dropped every table. Two tables that were never defined in the migrations folder were gone for good.
The agent had safety instructions. It reasoned past them.
That is the problem this solves: instructions are not a control. An agent that decides not to run something is a different thing from an agent that cannot run it without a human saying yes. vektor-guard is the second kind.
Install (2 minutes)
Add this to your MCP client config:
Claude Desktop — claude_desktop_config.json
(macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\)
{
"mcpServers": {
"vektor-guard": {
"command": "npx",
"args": ["-y", "-p", "vektor-guard", "vektor-guard-mcp"]
}
}
}Cursor — .cursor/mcp.json in your project, same shape.
Restart the client. The agent now has an inspect_sql tool it can call before running anything.
Tell it once, in your project rules or system prompt:
Before running any SQL that writes, alters, or drops, call
inspect_sqlfirst. If it returns BLOCKED, stop and ask me.
What it catches
| Operation | Why |
|---|---|
| DROP TABLE | Destroys a table and every row in it |
| TRUNCATE | Empties a table irreversibly |
| DELETE without WHERE | Removes every row |
| ALTER TABLE … DROP COLUMN | Destroys a column and its data |
| DROP DATABASE / DROP SCHEMA | Destroys everything |
| CREATE DATABASE | How a Prisma shadow-database step begins — the July case |
It is deliberately conservative, and it is not fooled by the usual ways a keyword hides:
-- caught: a comment between the keywords
DROP /* nothing to see here */ TABLE users;
-- NOT flagged: the keyword is data, not structure
INSERT INTO audit (note) VALUES ('someone ran DROP TABLE users');Statements are split quote-, comment- and dollar-quote-aware, and string literals are masked before the rules run.
Two levels
Free (what you just installed). Local pattern matching. Nothing leaves your machine — no connection string, no SQL, no telemetry. It tells you what is dangerous.
It cannot tell you how much is at stake, because it never connects to anything. "Deletes every row" is as specific as it gets.
With a Vektor API key. The same call is answered by Vektor's engine against your actual database:
BLOCKED — 1 destructive operation(s) found. Do NOT run this SQL.
[delete-without-where] DELETE without a WHERE clause removes every row in the table.
table: orders
rows at risk: 2,310,884
→ DELETE FROM orders{
"mcpServers": {
"vektor-guard": {
"command": "npx",
"args": ["-y", "-p", "vektor-guard", "vektor-guard-mcp"],
"env": {
"VEKTOR_API_KEY": "vk_live_...",
"VEKTOR_DATABASE_URL": "postgresql://..."
}
}
}
}The connection is opened read-only and the credential is used for the call and discarded — there is no apply path in the connector, and nothing is stored server-side.
If the engine is unreachable, it falls back to the local check and says so in the result. An unavailable engine never reads as "safe".
Get a key at vektor.dev.
Also a CLI
Same rules, no MCP client needed — useful in CI:
npx vektor-guard --file prisma/migrations/20260724_init/migration.sql
cat migration.sql | npx vektor-guard
npx vektor-guard "DELETE FROM users;"Exit codes: 0 clean · 2 blocked · 1 usage error. --allow-destructive downgrades blocks to warnings.
GitHub Actions:
- name: Check migrations for destructive operations
run: |
for file in $(git diff --name-only origin/main -- '**/migration.sql'); do
npx -y vektor-guard --file "$file"
doneLimits, stated plainly
- It is a lexical check, not a full SQL parser. It errs toward flagging.
- It cannot stop an agent that never calls it — it is a tool the agent must be told to use, not a network-level proxy.
- The free tier has no idea how big your tables are.
- It does not replace backups, PITR, or least-privilege database credentials. It is one layer.
Tests
node test.mjs # the rules
node test-mcp.mjs # the MCP protocol, end to endAbout
Extracted from the engine of Vektor — a desktop IDE for designing and safely operating PostgreSQL schemas. This part is MIT and always will be.
MIT © 2026 Vektor
