MSSQL Read-Only Query Skill
Execute safe, read-only queries against configured Microsoft SQL Server databases.
Requirements
- Python 3.8+
- pymssql:
pip install -r requirements.txt
Setup
Create connections.json in the skill directory or ~/.config/claude/mssql-connections.json.
Security: Set file permissions to 600 since it contains credentials:
chmod 600 connections.json
{
"databases": [
{
"name": "production",
"description": "Main app database - users, orders, transactions",
"host": "db.example.com",
"port": 1433,
"database": "app_prod",
"user": "readonly_user",
"password": "your-password",
"encrypt": true,
"tds_version": "7.3"
}
]
}
Config Fields
| Field |
Required |
Description |
| name |
Yes |
Identifier for the database (case-insensitive) |
| description |
Yes |
What data this database contains (used for auto-selection) |
| host |
Yes |
Database hostname |
| port |
No |
Port number (default: 1433) |
| database |
Yes |
Database name |
| user |
Yes |
Username |
| password |
Yes |
Password |
| encrypt |
No |
Enable TLS encryption (default: false) |
| tds_version |
No |
TDS protocol version: 7.0, 7.1, 7.2, 7.3, 7.4 (default: auto) |
Usage
List configured databases
python3 scripts/query.py --list
Query a database
python3 scripts/query.py --db production --query "SELECT TOP 10 * FROM users"
List tables
python3 scripts/query.py --db production --tables
Show schema
python3 scripts/query.py --db production --schema
Limit results
python3 scripts/query.py --db production --query "SELECT * FROM orders" --limit 100
Note: MSSQL uses TOP N instead of LIMIT. The --limit flag automatically inserts TOP N after SELECT.
Database Selection
Match user intent to database description:
| User asks about |
Look for description containing |
| users, accounts |
users, accounts, customers |
| orders, sales |
orders, transactions, sales |
| analytics, metrics |
analytics, metrics, reports |
| logs, events |
logs, events, audit |
If unclear, run --list and ask user which database.
Safety Features
- Read-only enforcement: Query validation blocks write operations (use a
db_datareader role user for server-side protection)
- Query validation: Only SELECT, SHOW, EXPLAIN, WITH, SP_HELP queries allowed
- Single statement: Multiple statements per query rejected
- TLS support: Configurable encryption for secure connections
- Query timeout: 30-second timeout enforced via pymssql
- Connection timeout: 10-second login timeout
- Memory protection: Max 10,000 rows per query to prevent OOM
- Column width cap: 100 char max per column for readable output
- Credential sanitization: Error messages don't leak passwords
Troubleshooting
| Error |
Solution |
| Config not found |
Create connections.json in skill directory |
| Authentication failed |
Check username/password in config |
| Connection timeout |
Verify host/port, check firewall/VPN |
| TDS version error |
Try "tds_version": "7.3" or "7.4" |
| Encryption error |
Set "encrypt": true for Azure SQL |
| Permission warning |
Run chmod 600 connections.json |
Exit Codes
- 0: Success
- 1: Error (config missing, auth failed, invalid query, database error)
Workflow
- Run
--list to show available databases
- Match user intent to database description
- Run
--tables or --schema to explore structure
- Execute query with appropriate
--limit (auto-converts to TOP N)
1---2name: workspace-mssql3description: Execute read-only SQL queries against multiple Microsoft SQL Server databases. Use when: (1) querying MSSQL/SQL Server databases, (2) exploring database schemas/tables, (3) running SELECT queries for data analysis, (4) checking database contents. Supports multiple database connections with descriptions for intelligent auto-selection. Blocks all write operations (INSERT, UPDATE, DELETE, DROP, etc.) for safety.4license: Apache-2.05---6
7# MSSQL Read-Only Query Skill
8
9Execute safe, read-only queries against configured Microsoft SQL Server databases.
10
11## Requirements
12
13- Python 3.8+
14- pymssql: `pip install -r requirements.txt`
15
16## Setup
17
18Create `connections.json` in the skill directory or `~/.config/claude/mssql-connections.json`.
19
20**Security**: Set file permissions to `600` since it contains credentials:
21```bash
22chmod 600 connections.json
23```
24
25```json
26{
27 "databases": [
28 {
29 "name": "production",
30 "description": "Main app database - users, orders, transactions",
31 "host": "db.example.com",
32 "port": 1433,
33 "database": "app_prod",
34 "user": "readonly_user",
35 "password": "your-password",
36 "encrypt": true,
37 "tds_version": "7.3"
38 }
39 ]
40}
41```
42
43### Config Fields
44
45| Field | Required | Description |
46|-------|----------|-------------|
47| name | Yes | Identifier for the database (case-insensitive) |
48| description | Yes | What data this database contains (used for auto-selection) |
49| host | Yes | Database hostname |
50| port | No | Port number (default: 1433) |
51| database | Yes | Database name |
52| user | Yes | Username |
53| password | Yes | Password |
54| encrypt | No | Enable TLS encryption (default: false) |
55| tds_version | No | TDS protocol version: 7.0, 7.1, 7.2, 7.3, 7.4 (default: auto) |
56
57## Usage
58
59### List configured databases
60```bash
61python3 scripts/query.py --list
62```
63
64### Query a database
65```bash
66python3 scripts/query.py --db production --query "SELECT TOP 10 * FROM users"
67```
68
69### List tables
70```bash
71python3 scripts/query.py --db production --tables
72```
73
74### Show schema
75```bash
76python3 scripts/query.py --db production --schema
77```
78
79### Limit results
80```bash
81python3 scripts/query.py --db production --query "SELECT * FROM orders" --limit 100
82```
83
84**Note**: MSSQL uses `TOP N` instead of `LIMIT`. The `--limit` flag automatically inserts `TOP N` after SELECT.
85
86## Database Selection
87
88Match user intent to database `description`:
89
90| User asks about | Look for description containing |
91|-----------------|--------------------------------|
92| users, accounts | users, accounts, customers |
93| orders, sales | orders, transactions, sales |
94| analytics, metrics | analytics, metrics, reports |
95| logs, events | logs, events, audit |
96
97If unclear, run `--list` and ask user which database.
98
99## Safety Features
100
101- **Read-only enforcement**: Query validation blocks write operations (use a `db_datareader` role user for server-side protection)
102- **Query validation**: Only SELECT, SHOW, EXPLAIN, WITH, SP_HELP queries allowed
103- **Single statement**: Multiple statements per query rejected
104- **TLS support**: Configurable encryption for secure connections
105- **Query timeout**: 30-second timeout enforced via pymssql
106- **Connection timeout**: 10-second login timeout
107- **Memory protection**: Max 10,000 rows per query to prevent OOM
108- **Column width cap**: 100 char max per column for readable output
109- **Credential sanitization**: Error messages don't leak passwords
110
111## Troubleshooting
112
113| Error | Solution |
114|-------|----------|
115| Config not found | Create `connections.json` in skill directory |
116| Authentication failed | Check username/password in config |
117| Connection timeout | Verify host/port, check firewall/VPN |
118| TDS version error | Try `"tds_version": "7.3"` or `"7.4"` |
119| Encryption error | Set `"encrypt": true` for Azure SQL |
120| Permission warning | Run `chmod 600 connections.json` |
121
122## Exit Codes
123
124- **0**: Success
125- **1**: Error (config missing, auth failed, invalid query, database error)
126
127## Workflow
128
1291. Run `--list` to show available databases
1302. Match user intent to database description
1313. Run `--tables` or `--schema` to explore structure
1324. Execute query with appropriate `--limit` (auto-converts to TOP N)