Chat2DB is a free, cross-platform, local-first database client and SQL workspace for developers, DBAs, analysts, and data teams. Connect to 40+ databases, manage data, edit and run SQL, and use your own AI model to generate, explain, and optimize queries. Available on desktop, web, Docker, and CLI, with MCP support.
- capability exposure inferred + 35
- tool safety inferred + 5
- trust mitigators mixed − 8
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 9m ago · see ecosystem CVEs →
- A · 0 → B · 32
No known CVEs for this server.
- medium dangerous code
dynamic exec: new Function()
analyzed commit f8b8f98 · analyzer v32 · 1h ago
skills & prompt files 1
- agent-rules OtterMind-Chat2DB-f8b8f98/AGENTS.md
danger signals3
- dynamic code execution new Function() OtterMind-Chat2DB-f8b8f98/chat2db-community-client/dist.zip!/dist/3523.async.js :8
={},f=34,s=10,t=13;function r(y){return new Function("d","return {"+y.map(function(w,S){return JSON.stringify(w)+": d["+S+'] || ""'}).join(",")+"}")}function p(y,w){var S=r(y);return function(P,B){ret - dynamic code execution new Function() OtterMind-Chat2DB-f8b8f98/chat2db-community-client/dist.zip!/dist/npm.echarts.async.js :3
!="undefined"&&JSON.parse?JSON.parse(a):new Function("return ("+a+");")():a}var Jn=(0,c.kW)(),Xr={registerMap:function(a,e,t){if(e.svg){var r=new Ag(a,e.svg);Jn.set(a,r)}else{var n=e.geoJson||e.geoJSO - dynamic code execution new Function() OtterMind-Chat2DB-f8b8f98/chat2db-community-client/src/utils/index.ts :30
return new Function('return ' + data.toString())();
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of OtterMind.