Veto — SQL Safety & Cost Oracle
Deterministic safety, correctness & cost gate that vets Postgres SQL before your AI agent runs it.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"veto": {
"url": "https://vetosql.com/mcp"
}
}
}Remote endpoints
https://vetosql.com/mcpstreamable-httpWhat it can do
Tool inventory
Tools (3)
🟡analyze_sql(sql, schema, rowCountHints, dialect)
Analyze Postgres SQL/migrations for destructive operations, locking risk, correctness traps (NULL handling that silently returns wrong results), anti-patterns, and query cost. Returns a deterministic verdict (ok/warn/block) with findings. Pass the optional `schema` argument (your CREATE TABLE/INDEX DDL) to also get EXPLAIN-based cost analysis run on a throwaway scratch Postgres — no separate tool or DB connection needed.
Input Schema
{
"type": "object",
"properties": {
"sql": {
"type": "string",
"description": "The SQL to analyze (one or more statements)."
},
"schema": {
"type": "string",
"description": "Optional CREATE TABLE/INDEX DDL. Providing it enables EXPLAIN-based cost analysis (seq scans on large tables, etc.) on a throwaway scratch Postgres; omit it for static safety analysis only."
},
"rowCountHints": {
"type": "object",
"additionalProperties": {
"type": "number"
},
"description": "Optional map of table name to estimated row count for realistic cost estimates."
},
"dialect": {
"type": "string",
"const": "postgres"
}
},
"required": [
"sql"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴set_policies(policies)
Replace the stored custom org policy set for your Pro key (this is also how you update or clear them: send the full new set to update, or an empty array to remove all). Each policy blocks or warns on an operation against matching tables (e.g. no DELETE on payments). Policies are declarative data — validated, never executed — and apply transparently to every later analyze_sql call made with this key. Use get_policies to read the current set.
Input Schema
{
"type": "object",
"properties": {
"policies": {
"type": "array",
"items": {
"type": "object",
"properties": {
"table": {
"type": "string",
"description": "Exact table name or glob, e.g. \"payments\", \"audit_*\", \"*\"."
},
"operations": {
"type": "array",
"items": {
"type": "string",
"enum": [
"select",
"insert",
"update",
"delete",
"truncate",
"drop",
"alter"
]
},
"description": "Operations this rule applies to."
},
"action": {
"type": "string",
"enum": [
"block",
"warn"
]
},
"message": {
"type": "string",
"description": "Optional human message shown in the finding."
}
},
"required": [
"table",
"operations",
"action"
],
"additionalProperties": false
},
"description": "The full policy set (replaces any previously stored set; max 50)."
}
},
"required": [
"policies"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡get_policies
Return the custom org policy set currently stored for your Pro key — the same rules analyze_sql enforces on top of the built-ins. Read-only; returns an empty list if none are set. Use set_policies to change them.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence