Wes Ellis./ a personal notebook
Technology. Stories. Side projects.
A few things worth writing down.
← Back to Engineering

Engineering

Three MCP Servers I'd Install First: GitHub, Trello and a Database

Network cables plugged into two wall jacks, one of them glowing red.

Part 4 of the thread Building with Claude and MCP

THE SHORT VERSION4 points
  • GitHub now ships its own MCP server. The old npm package in my notes is deprecated.
  • The Trello server in my notes is still maintained, but the API key page moved.
  • The reference Postgres server is archived, and it had a read-only bypass. Use a maintained one, with a read-only database user.
  • Start every server with the least access that does the job, then widen it on purpose.

When I wrote my MCPModel Context Protocol. An open standard for plugging tools and data sources into an AI model, so it can call them in the middle of a conversation.More: MCP Tool Poisoning, and Why G8KEPR Fingerprints Every Tool notes, I did one guide per server: GitHub, Trello and databases. They're still the three I'd reach for first. But when I checked them against the current docs, every one of them had moved. One package is deprecated, one setup page changed, and one server was archived after a security write-up. So this is the corrected version.

If you haven't added a server before, setting up MCP servers from scratch covers the basics.

Checked against the docs in September 2026.

GitHub

The package in my notes, @modelcontextprotocol/server-github, is marked "no longer supported" on npm. Development moved to GitHub's own server, github/github-mcp-server.

The easiest way in is GitHub's hosted version, which is just a URL and a token. Its install guide for Claude Code uses add-json, and I've added the header that makes it read-only:

claude mcp add-json github '{"type":"http","url":"https://api.githubcopilot.com/mcp","headers":{"Authorization":"Bearer <your-github-pat>","X-MCP-Readonly":"true"}}'

If you'd rather run it locally, there's a Docker image:

claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=<your-github-pat> -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server

For the local version, read-only is the --read-only flag or GITHUB_READ_ONLY=1. You can also trim it to certain toolsets (repos, issues, pull requests and so on) so Claude doesn't see forty tools when it needs four.

For the token, GitHub recommends a fine-grained personal access token over a classic one, scoped to the repos you actually want touched. My old notes said "classic token with repo and workflow." That's the widest door in the house.

Trello

The server I noted, delorenj/mcp-server-trello, is alive and well. It has grown to 57 tools and it remembers your active board between sessions in ~/.trello-mcp/config.json. Its README uses bunx and says npx works the same:

claude mcp add trello --env TRELLO_API_KEY=<your-api-key> --env TRELLO_TOKEN=<your-token> -- npx -y @delorenj/mcp-server-trello

Two things changed since my note. TRELLO_BOARD_ID is now marked deprecated, because you pick the board in conversation with set_active_board instead. And the old app-key page isn't where keys come from anymore. Atlassian's docs now have you create a Power-Up in the admin portal at trello.com/apps/admin, generate the API key there, and get the token from the link next to it.

Trello allows 300 requests per 10 seconds per key and 100 per 10 seconds per token, and the server throttles itself to fit. The token can do anything your Trello account can, so keep it out of anything you commit.

A database

This is the one that changed most. The reference Postgres server from my notes, @modelcontextprotocol/server-postgres, has been deprecated and archived. It was meant to be read-only, running every query inside a read-only transaction. In 2025, Datadog Security Labs showed that a query could close that transaction and run whatever came after it, writes included.

My notes also listed a MySQL package, @modelcontextprotocol/server-mysql. It doesn't exist. And the SQLite reference server is archived too.

What's maintained now:

  • Postgres MCP Pro (crystaldba/postgres-mcp). Run it with --access-mode=restricted for read-only transactions and a time limit on queries.
  • MCP Toolbox for Databases from Google (googleapis/genai-toolbox), which covers Postgres, MySQL and a long list of others.

Whichever you use, the lock that matters most is the database user. Give the server a login that can only read, so even a clever query can't write:

CREATE ROLE claude_readonly WITH LOGIN PASSWORD '<choose-a-password>';
GRANT CONNECT ON DATABASE app TO claude_readonly;
GRANT USAGE ON SCHEMA public TO claude_readonly;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO claude_readonly;

Warning

Point it at a copy or a staging database first. "Read-only" in a server's settings is a promise from that server. A read-only role is a promise from the database, and that's the one I trust.

Why least access matters here

Put these three together and you've built the setup that makes security people wince: private data, untrusted content and a way to act on it. A GitHub issue is text written by a stranger, and the model reads every word of it. That's prompt injection in its natural habitat, and it's the pattern behind the lethal trifecta.

Server Start with Widen when
GitHub Read-only, a few toolsets, fine-grained token You want Claude opening PRs, not merging them
Trello One board, a token you can revoke You trust the workflow
Database Read-only role, staging copy Rarely. Migrations are a job for you

Each server's tool descriptions also go straight into the model's context, which is another way in. I wrote about that one in MCP tool poisoning.

None of this makes MCP scary. It just makes it plumbing, and you install plumbing with the water off.