Use MCP for read-only SQL first

A database MCP with a writer role is a production incident. Start with SELECT and a LIMIT.

Create a read-only user. Point the server at that DSN. Do not reuse the migrator password from CI.

The first call should be a bounded SELECT: named columns, a LIMIT, a known table. If the tool wants INSERT to try it, stop.

Schema inspection is useful. Dumping a whole table is not. If results blow the window, read the tool-result-size guide.

Filter this directory database category. Prefer entries that say read-only in the description.