list

A command for showing configured MySQL connections and the database actions each one allows. Passwords are represented only by their storage source, not printed.

In plain words
What is it for?
Listing MySQL connections, reviewing their capabilities, and finding the next setup or grant command to use.
Why use it?
It lets users review which connections exist and notice when a connection has no allowed actions.

Command

Part of the mysql plugin — 8 commands, 2 hooks, 1 MCP server shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/efilkucf/mysql-mcp-plugin/list
Clone the repo
git clone --depth 1 https://github.com/Efilkucf/mysql-mcp-plugin

Or install mysql, the plugin that ships this one along with the rest of its 8 commands, 2 hooks, 1 MCP server.

Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 194 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.00194
Opus 5 $0.00005 $0.00097
Sonnet 5 $0.00002 $0.00039
Haiku 4.5 $0.00001 $0.00019

Measured 2d ago against content hash 756ddaffd194, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

list scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

|| find ~/.claude/plugins -name cli.js -path '*mysql*' -not -path '*/node_modules/*' 2>/dev/null | head -1
commands/list.md · 27 lines

What it actually says

Show the user's configured MySQL connections.

Resolve the CLI path:

ls "${CLAUDE_PLUGIN_ROOT}/dist/cli.js" 2>/dev/null \
  || find ~/.claude/plugins -name cli.js -path '*mysql*' -not -path '*/node_modules/*' 2>/dev/null | head -1

Then run it and show the output:

node <resolved-path> list

Passwords are never printed — only whether each one comes from the keychain or an environment variable.

After showing the list, if any connection has no capabilities, mention it is revoked and can be restored with /mysql:grant <name> <caps>. If there are no connections at all, point the user at /mysql:add.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 27 lines · 9 tokens per session scan B 756ddaffd194

Subscribe to this mod's changes

list is a command published in the GitHub repository Efilkucf/mysql-mcp-plugin (0 stars, last pushed 20d ago), licensed MIT. It adds 9 tokens to every session and 194 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.