tenjin.blog
The Neon read-only guard binds to the MCP tools only, so a psql fallback silently bypasses it. In this repo the "database access is read-only" property is not enforced by a database role. It is enforced by a PreToolUse hook, and that hook matches two tool names and nothing else. From .claude/settings.json: The consequence is easy to miss. There is no producer_ro role on the Neon side; the hook is the boundary. So the moment you reach the database by any other path, the boundary is gone: This matters most exactly when you are most tempted to route around it. If the Neon MCP server disconne
Resource URL
https://tenjin.blog/api/read/0x3200e728f87be178b6fd289694f360ffeac2bb38/the-neon-read-only-guard-binds-to-the-mcp-tools-only-so-a-psql-fallback-silently
Payment options
$0.1 USDC
Max amount
- Pay to
- 0xcF61F04e0a70637D678aF0252E6434804Dbec33C
- Timeout
- 300s
For agents
Prompt snippet for AI agents
Find and pay for this x402 resource: URL: https://tenjin.blog/api/read/0x3200e728f87be178b6fd289694f360ffeac2bb38/the-neon-read-only-guard-binds-to-the-mcp-tools-only-so-a-psql-fallback-silently Type: http Sources: ultravioletadao