本文へ移動
cccskills
無料GitHub で公開

relational-database-mcp-cloudbase

[Deprecated] This is the required documentation for agents operating on the CloudBase Relational Database through MCP. It defines the canonical SQL management flow with `queryMysqlDatabase`, `manageMysqlDatabase`, `queryPermissions`, and `managePermissions`, including destroy flow, async status checks, safe query execution, schema initialization, and permission updates. MySQL provisioning is no longer available through MCP; new environments should use PostgreSQL — see postgresql-development skill instead.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md10.5 KB
  • LICENSE.md1.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Sibling skills (local only)

Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.

If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.

Activation Contract

Use this first when

  • The agent must inspect SQL data, execute SQL statements, destroy an existing MySQL instance, initialize table structure, or manage table security rules through MCP tools.

Read before writing code if

  • The task includes queryMysqlDatabase, manageMysqlDatabase, queryPermissions, or managePermissions.

Then also read

  • Web application integration -> ../relational-database-web-cloudbase/SKILL.md
  • Raw HTTP database access -> ../http-api-cloudbase/SKILL.md

Do NOT use for

  • Frontend or backend application code that should use SDKs instead of MCP operations.

Common mistakes / gotchas

  • Initializing SDKs in an MCP management flow.
  • Running write SQL or DDL before confirming the environment already has a ready MySQL instance.
  • Trying to create a MySQL instance through MCP. Provisioning has been retired from the tool surface: new environments use PostgreSQL, and instances are only created in the console.
  • Treating document database tasks as MySQL management tasks.
  • Skipping _openid and permissions review after creating new SQL tables.
  • Destroying MySQL without explicit confirmation or without checking whether the environment still needs the instance.
  • Using getConnectionInfo (or inferred host/password) to build a default TCP client for new apps. Prefer SDK / runQuery / runStatement; TCP credentials are an explicit migration exception only.

When to use this skill

Use this skill when an agent needs to operate on CloudBase Relational Database via MCP tools, for example:

  • Inspecting or querying SQL data
  • Destroying an existing MySQL instance
  • Polling an in-flight MySQL task (create tasks are started in the console — MCP no longer creates instances)
  • Modifying data or schema (INSERT/UPDATE/DELETE/DDL)
  • Initializing tables and indexes after MySQL is ready
  • Reading or changing table permissions

Do NOT use this skill for:

  • Building Web or Node.js applications that talk to CloudBase Relational Database directly through SDKs
  • Auth flows or user identity management

How to use this skill (for a coding agent)

  1. Recognize MCP context

    • If you can call tools like queryMysqlDatabase, manageMysqlDatabase, queryPermissions, managePermissions, you are in MCP context.
    • In this context, never initialize SDKs for CloudBase Relational Database; use MCP tools instead.
  2. Pick the right tool for the job

    • Read-only SQL and create/destroy task status checks -> queryMysqlDatabase
    • MySQL destruction, write SQL, DDL, schema initialization -> manageMysqlDatabase
    • Inspect permissions -> queryPermissions(action="getResourcePermission")
    • Change permissions -> managePermissions(action="updateResourcePermission")
  3. Always be explicit about safety

    • Before destructive operations (DELETE, DROP, etc.), summarize what you are about to run and why.
    • Prefer queryMysqlDatabase(action="getInstanceInfo") or a read-only SQL check before writes.
    • Destroying MySQL requires explicit confirmation because it has environment-level impact; provisioning is not offered here at all.

Available MCP tools (CloudBase Relational Database)

These tools are the supported way to interact with CloudBase Relational Database via MCP:

1. queryMysqlDatabase

  • Purpose: Query SQL data and instance / task state.
  • Use for:
    • Running SELECT and other read-only SQL queries with action="runQuery"
    • Checking whether MySQL already exists with action="getInstanceInfo" (lifecycle only — no connection credentials)
    • Inspecting an in-flight create or destroy task with action="describeCreateResult" or action="describeTaskStatus" (create tasks originate in the console)
    • Exception only: action="getConnectionInfo" returns the raw connection/cluster payload (may include credentials) for migrating existing TCP/ORM clients. Do not use this for new business CRUD — prefer Web/Node SDK or runQuery / runStatement.

Example flow:

{
  "action": "runQuery",
  "sql": "SELECT id, email FROM users ORDER BY created_at DESC LIMIT 50"
}

Do NOT call getConnectionInfo and then wire pymysql / mysql2 / DATABASE_URL into a cloud function for greenfield apps. Platform-delegated SQL and SDK access are the default.

2. manageMysqlDatabase

  • Purpose: Manage an existing SQL instance and execute mutating SQL.
  • Use for:
    • Destroying MySQL with action="destroyMySQL"
    • Executing INSERT, UPDATE, DELETE, CREATE TABLE, ALTER TABLE, DROP TABLE with action="runStatement"
    • Initializing tables and indexes with action="initializeSchema"

Provisioning is not available here. provisionMySQL has been removed from the action set: a call carrying it fails schema validation, and a missing instance returns MYSQL_NOT_CREATED with a console entry rather than a create hint.

Important: When creating a new table, you must include the _openid column for per-user access control:

_openid VARCHAR(64) DEFAULT '' NOT NULL

Note: when a user is logged in, _openid is automatically populated by the server from the authenticated session. Do not manually fill it in normal inserts.

Before calling this tool, confirm:

  • The current environment already has a ready MySQL instance.
  • The target tables and conditions are correct.
  • You have run a corresponding read-only query when appropriate.

When destroying MySQL, confirm:

  • The current environment really should lose the SQL instance.
  • You have explicit confirmation for the destructive action.
  • You are prepared to query describeTaskStatus afterward to inspect the destroy result.

3. queryPermissions

  • Purpose: Read permission configuration for a given SQL table.
  • Use for:
    • Understanding who can read/write a table
    • Auditing permissions on sensitive tables
    • Call shape: queryPermissions(action="getResourcePermission", resourceType="sqlDatabase", resourceId="<tableName>")

4. managePermissions

  • Purpose: Set or update permissions for a given SQL table.
  • Use for:
    • Hardening access to sensitive data
    • Opening up read access while restricting writes
    • Updating resource-level permission configuration
    • Call shape: managePermissions(action="updateResourcePermission", resourceType="sqlDatabase", resourceId="<tableName>", permission="READONLY")

Compatibility

  • Canonical plugin name: permissions
  • Legacy plugin aliases security-rule, security-rules, secret-rule, secret-rules, and access-control are still routed to permissions
  • Legacy tools readSecurityRule and writeSecurityRule are removed; always use queryPermissions and managePermissions

Recommended lifecycle flow

Scenario 1: The environment has no MySQL instance

  1. Call queryMysqlDatabase(action="getInstanceInfo").
  2. If no instance exists, stop. MySQL provisioning is no longer available through MCP: the result is MYSQL_NOT_CREATED with a console entry and no create hint.
  3. New environments should use CloudBase PostgreSQL — see ../postgresql-development-cloudbase/SKILL.md.
  4. An instance created outside the tool can still be observed: poll queryMysqlDatabase(action="describeCreateResult") or queryMysqlDatabase(action="describeTaskStatus"), and only continue once the lifecycle status is READY.
  5. Reserve describeTaskStatus for destroy flows whose task response carries TaskName.

Scenario 2: Safely inspect data in a table

  1. Use queryMysqlDatabase(action="runQuery") with a limited SELECT.
  2. Include LIMIT and relevant filters.
  3. Review the result set and confirm it matches expectations before any write operation.

Scenario 3: Apply schema initialization on a ready instance

  1. Confirm MySQL is ready.
  2. Prepare ordered DDL statements.
  3. Run them through manageMysqlDatabase(action="initializeSchema").
  4. After creating tables, verify permissions with queryPermissions or managePermissions.

Scenario 4: Execute a targeted write or DDL change

  1. Use queryMysqlDatabase(action="runQuery") to inspect current data or schema if needed.
  2. Run the mutation once with manageMysqlDatabase(action="runStatement").
  3. Validate with another read-only query or by checking security rules.

Scenario 5: Destroy MySQL when the environment no longer needs it

  1. Use queryMysqlDatabase(action="getInstanceInfo") to confirm the current environment still has a SQL instance.
  2. Call manageMysqlDatabase(action="destroyMySQL", confirm=true).
  3. Query queryMysqlDatabase(action="describeTaskStatus") until the destroy task completes or fails.
  4. If the task succeeds, optionally call queryMysqlDatabase(action="getInstanceInfo") to confirm the instance no longer exists.
  5. If the task fails, treat the returned error as the terminal result and let the caller decide whether to retry.

Key principle: MCP tools vs SDKs

  • MCP tools are for agent operations and database management:

    • Inspect and manage an existing MySQL instance — never create one.
    • Destroy MySQL.
    • Poll lifecycle state.
    • Run ad-hoc SQL.
    • Inspect and change resource permissions.
    • Do not depend on application auth state.
  • SDKs are for application code:

    • Frontend Web apps -> Web Relational Database skill.
    • Backend Node apps -> Node Relational Database quickstart.

When working as an MCP agent, always prefer these MCP tools for CloudBase Relational Database, and avoid mixing them with SDK initialization in the same flow.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the `model` field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*, model id in the `model` field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper `model` field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs).

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

Use when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes, or missing contract tests, especially during periodic quality review or before preparing corrective PRs.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloudBase/CloudBase-AI-Toolkit1,1362026年10月11日 更新

TencentCloudBase のスキルをすべて見る

このスキルの問題を報告する