ClickHouse MCP Server connects AI assistants to ClickHouse, a database system for querying and analyzing data. It exposes tools for running read-only SQL queries and inspecting databases and tables, and the catalogue entries help agents connect to and use that server.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/clickhouse/mcp-clickhouse/agents-mdgit clone --depth 1 https://github.com/ClickHouse/mcp-clickhouseWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/clickhouse/mcp-clickhouse/agents-md)<a href="https://agentmods.dev/instructions/clickhouse/mcp-clickhouse/agents-md"><img src="https://agentmods.dev/badge/instructions/clickhouse/mcp-clickhouse/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01969 | $0.01969 |
| Opus 5 | $0.00984 | $0.00984 |
| Sonnet 5 | $0.00394 | $0.00394 |
| Haiku 4.5 | $0.00197 | $0.00197 |
Grade A, and why
mcp-clickhouse AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 148 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Instructions
AGENTS.md is the canonical instruction file for AI agents working in this repository. If another agent-facing file disagrees with this one, this file wins.
Before making substantial changes, read README.md, pyproject.toml, and the relevant source and tests. The README is part of the user-facing contract because it documents tools, response shapes, security behavior, and every supported environment variable.
Role
Act like an experienced maintainer of a public Python MCP server and database integration.
- Think about the MCP client experience, ClickHouse behavior, operational safety, and maintainability together.
- Be opinionated and practical. Do not over-engineer.
- Do not engage in sycophancy.
- If an assumption could materially affect security, compatibility, or the public tool contract, verify it or call it out explicitly.
Project Map
mcp_clickhouse/mcp_server.py: FastMCP server construction, tool and prompt registration, ClickHouse and chDB execution, pagination, authentication, health checks, and response serialization.mcp_clickhouse/mcp_env.py: environment-backed configuration and validation. Treat this as the source of truth for configuration semantics.mcp_clickhouse/main.py: runtime entry point and transport startup.mcp_clickhouse/mcp_middleware_hook.py: optional user-provided middleware loading.mcp_clickhouse/chdb_prompt.py: the public chDB prompt content.mcp_clickhouse/skills_advisor.py: server-level instructions advertised to MCP clients.tests/: unit, integration, FastMCP client, pagination, auth, middleware, and optional-dependency coverage.test-services/docker-compose.yaml: local ClickHouse service for integration tests..github/workflows/ci.yaml: authoritative CI commands and CI ClickHouse version.
Working Rules
- Understand the full local context before changing code. Inspect the implementation, its callers, adjacent tests, and documented behavior.
- Keep changes small, safe, and directly tied to the task.
- Preserve backward compatibility by default. Tool names, tool arguments, JSON response shapes, prompt names, environment variables, defaults, and error behavior are public interfaces.
- Do not add dependencies without a strong reason. Keep chDB optional.
- Follow the surrounding style and write idiomatic Python compatible with Python 3.10 and later.
- Use double quotes for new Python strings unless the surrounding syntax makes another choice clearer.
- Place imports at the top of the file. The deliberate lazy
chdb.sessionimport is an exception and must remain lazy unless the optional-dependency design changes. - Prefer
rgfor repository search. - Use
uvfor dependency and command execution. Do not hand-edituv.lock. - Do not modify unrelated user changes in a dirty worktree.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed 45d4f955d37b
- 6d ago First seen · 148 lines · 1,969 tokens per session scan A 02016dbb2aa6
mcp-clickhouse AGENTS.md is an instructions file published in the GitHub repository ClickHouse/mcp-clickhouse (866 stars, last pushed yesterday), licensed Apache-2.0. It adds 1,969 tokens to every session, about $0.0098 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
lms-front CLAUDE.md
Claude Code instructions for guillermoscript/lms-front, covering claude.md, project overview, commands, architecture and multi-tenancy.
vespertide AGENTS.md
AGENTS.md instructions for dev-five-git/vespertide, covering vespertide knowledge base, structure, where to look, data flow and conventions.
seekstone CLAUDE.md
Claude Code instructions for shaqmughal/seekstone, covering claude.md, what this repo is, commands, the harness itself (run after npm install) and architecture.
rails_ai_agents AGENTS.md
AGENTS.md instructions for ThibautBaissac/rails_ai_agents, covering project configuration, tech stack, architecture, key commands and tests.
pg-dash CLAUDE.md
Claude Code instructions for indiekitai/pg-dash, covering pg-dash claude.md, 项目结构, 构建与测试, 发版纪律(强制) and 发版检查清单(每次 npm publish 前必须按序执行).
MCP-SqlServer CLAUDE.md
Claude Code instructions for Aron-Valenzuela/MCP-SqlServer, covering claude.md, project overview, setup (for each user), 1. install dependencies and 2. configure claude desktop.