Mgc Database Security
Secure database credential management using MGC Blackbox 1.5.2. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext.
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
1.3.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.3.0release · observed Sep 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s173fckt3bzxxvt9dfp0rrdeg1894z72:mgc-database-security- Install using `clawhub skill install s173fckt3bzxxvt9dfp0rrdeg1894z72:mgc-database-security` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zkeviny/mgc-database-security before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
144,857 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
spec: usk/3.0
id: data-analyst-secure-suite
version: 1.3.0
name: Secure Data Analyst Skill Suite
description: A secure data analysis workflow suite based on MGC Blackbox 1.5.2+, providing credential protection, zero-exposure script & workflow application, sealed-package collaboration, and knowledge management. Supports MGC 1.5.2 workflow auto-recognition (import / from-import / relative paths / subprocess runtime routing). Includes a Data Analyst Agent system prompt template.
author: MirginCipher Team
license: MIT
tags: security, data analysis, mgc, zero-exposure, local sandbox, credential management, workflow management, sealed collaboration, knowledge management, agent template, fuzzy search, auto-recognized workflow, sealed cross-script
platform_compatibility: windows, macos, linux
requires:
mgc_blackbox: ">=1.5.2"
changelog:
- version: 1.3.0
changes:
- Upgraded to MGC 1.5.2+: added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging).
- Script management refactor: upgraded from single-script to workflow-folder mode, with import / from-import / relative-path / subprocess auto-recognition.
- Credential management: unified info_type from 'credential' to 'token' to align with skill_spec.
- Added prompts/collaboration_management.md: dedicated workflow / skill-package sealed-authorization guide.
- Agent template: workflow examples upgraded from 5-step manual chain to find -> save_file -> run pattern.
- Added sealed-collaboration chapter (mgc_seal_package one-click seal of an entire workflow).
- Added recognizable cross-script patterns table (from-import / import / Path / subprocess).
- MCP tools list expanded to 10 (added mgc_save_file, mgc_seal_package, mgc_package).
- version: 1.2.0
changes:
- Synced with MGC Blackbox 1.4.10: added mgc_find (fuzzy search) and mgc_run (preferred over mgc_get action=run).
- Script management: replaced mgc_get(action='run') with dedicated mgc_run tool.
- Script management: added mgc_find workflow for locating scripts by name.
- Script sealing: clarified ext04 must be a multi-line PEM public key.
- Credential management: added mgc_find workflow.
- Knowledge management: added mgc_find workflow.
- Agent system prompt: documented the find -> get/run workflow pattern.
- version: 1.1.1
changes:
- Optimized documentation structure per review report
- Added 'Anti-patterns and pitfalls' chapter
- Added 'Complete use cases' chapter
- Unified prompt file-name references
- version: 1.1.0
changes:
- Consolidated prompts into three core modules: credential, script, knowledge management
- Added agent_system_prompt.md as a Data Analyst Agent system-prompt template
- Strengthened document structure and clarified each module's scenario and invocation
- version: 1.0.0
changes:
- Initial release
---
# OverviewREADME.md
# Secure Data Analyst Skill Suite # Secure Data Analyst Skill Suite > **Version**: 1.3.0 · **Requires**: MGC Blackbox ≥ 1.5.2 A secure data-analysis workflow suite built on **MGC Blackbox**, providing a hybrid mix of **skill prompts + Agent system-prompt template**, helping data analysts securely manage scripts, workflows, credentials, sealed collaboration, and knowledge on the local machine. --- ## What this suite is This suite helps data analysts complete data-analysis workflows locally and securely: - **Database credential security** (zero exposure) - **Application of user-owned scripts & workflows** (query / clean / analyze) - **Auto-recognized workflows** (import / from-import / relative-path / subprocess runtime routing, 1.5.2+) - **Sealed-collaboration on workflows / skill packages** (one-key-per-node, node-bound, no resell, 1.5.2+) - **Knowledge management for analysis methods & prompts** (local encrypted storage) - **Optional Data Analyst Agent template** (auto-enforces the security boundary) All sensitive operations require explicit user authorization. This suite does not provide any automated data-access capability. --- ## Prerequisites - Python 3.10+ - Install MGC Blackbox: ``` pip install mgc-blackbox>=1.5.2 ``` - Start MGC: ``` mgc ``` - Available MCP tools: mgc_save, mgc_save_file, mgc_get, mgc_run, mgc_seal, mgc_seal_package, mgc_package, mgc_list, mgc_find, mgc_open_webui - Token file: `~/.mgc/database/mgc_black_box/.mgc_token` --- ## Core capabilities ### 1. Credential management (`credential_management.md`) Securely store and use database keys, API tokens, and other secrets. **Scenarios** - Need to connect to databases or external services - Scripts need safe access to credentials - Team members share database/service **access rights** (not the data itself) - Team members share **analysis methods and scripts** across the team and outside (via workflow sealed authorization) **What it provides** - Local encrypted storage - AI never sees the plaintext credentials - Scripts can call credentials with zero exposure - All accesses require user authorization **How the agent uses it** The agent, after user authorization, reads credentials but never sees plaintext. --- ### 2. Workflow management (`script_management.md`) Manage user-owned query / clean / analyze scripts — both as single scripts and as workflow folders. **Scenarios** - User wants to apply their own scripts or workflows - Scripts need safe access to credentials - Multi-script workflows need auto-recognition of import / subprocess call relationships (1.5.2+) - Workflows need cross-team collaboration (sealed) - Need to build a complete data-analysis chain (query → clean → analyze) **What it provides** - Single-script encrypted storage (`mgc_save`) - Workflow-folder encrypted storage with auto-recognition of import / subprocess (`mgc_save_file`, 1.5.2+) - AI never sees the script content - Scripts call credentials with zero exposure - Single-
_meta.json
{
"ownerId": "kn7dbqpp9139vnzrg035qhwfk18947vg",
"slug": "mgc-database-security",
"version": "1.3.0",
"publishedAt": 1790653285591
}agent_system_prompt.md
# Secure Data Analyst Agent — System Prompt Template (Safety Version)
You are a **Secure Data Analyst Workflow Assistant** that helps data analysts use MGC Blackbox (≥ 1.5.2) to securely manage and apply their own scripts and workflows on the local machine.
You are NOT an automated execution engine. You must strictly obey the security boundary and obtain explicit user authorization before any sensitive operation.
---
## Your role
You are a **workflow assistant**, not an automation engine.
Your goal is, after the user authorizes it, to safely apply the user's scripts and workflows via MGC Blackbox and to assist in managing the full workflow.
You must not make decisions on behalf of the user, and you must not execute anything without authorization.
---
## Security boundary you must obey
### You must NEVER:
- Access any credential without user authorization
- Access or view script content without user authorization
- Generate, modify, or infer user scripts
- Apply scripts or workflows without user authorization
- Transmit any data to an external system
- Chain multiple workflow steps without explicit confirmation
- Auto-select a script name (`info_owner` must be explicitly supplied by the user)
- Automate data access, cleaning, analysis, or transport
### You MUST:
- Request user authorization before any sensitive operation
- Only apply scripts and workflows through MGC Blackbox
- Return results without exposing script logic
- Only use user-owned scripts
- Ensure all operations happen on the user's local machine
- Refer to the prompts in this skill suite when the user asks about workflows
---
## How to use this skill suite
### 1. Credential management
When the user wants to store credentials:
```
Ask: "Do you authorize storing these credentials in MGC?"
- If yes: direct the user to the MGC WebUI
- You NEVER handle credential content directly
```
---
### 2. Workflow application (find → save_file → run, 1.5.2+)
When the user requests running a data-analysis workflow, use the **find → run** self-describing workflow:
```
Step 1 — Locate the workflow (mgc_find, fuzzy-search by name):
matches = mgc_find(
info_owner="<partial name>", # e.g. "monthly_sales" matches "monthly_sales_analysis"
)
# matches returns a metadata list — NEVER plaintext.
# If multiple matches, ask the user to disambiguate; if exactly one, proceed.
Step 2 — Request authorization:
"Do you authorize running the workflow <info_owner from matches>?"
Step 3 — If authorized, run the workflow through MGC:
result = mgc_run(
info_owner="<info_owner>",
diff_2="<info_owner>",
)
# MGC auto-recognizes the package's import / subprocess relationships and routes through sealed execution.
# Returns {"pid": 12345, "status": "started"}
Step 4 — Return the run status without exposing script logic
```
> **Note**: Workflow output must be written to an explicit file path, or into a database / MGC itself. MGC never returns plaintext script content.
---
### 3. Single-scripprompts/collaboration_management.md
# Workflow & Skill Package Sealed Collaboration
This document guides data analysts on how to securely seal and deliver workflows or skill packages to other nodes in **MGC Blackbox ≥ 1.5.2**, enabling "usable but unreadable, runnable but unresellable" cross-team / cross-organization collaboration.
All sensitive operations must be explicitly authorized by the user before proceeding.
---
# 1. Why Sealed Collaboration Is Needed
Common collaboration pain points in data analysis workflows:
| Scenario | Pain Point | MGC Solution |
|----------|-----------|--------------|
| Data team delivers analysis workflow to business team | Don't want business team to see source code or modify logic | After workflow sealing, recipient can only run, never read |
| External analyst delivers analysis package to customer | Customer resells source to peers after delivery | AES key bound to customer node, cannot re-seal |
| Cross-department sharing of analysis methodology | Worry about core algorithm leakage | Seal the entire workflow at once, core algorithms locked inside scripts |
| Delivering to multiple customers | Each customer needs independent authorization | One key per customer, each customer has independent key |
> **Core principle**: Delivery equals authorization. After sealing, the recipient can only run — cannot read, modify, or resell.
---
# 2. Workflow Sealing vs Skill Package Sealing
MGC supports two sealed collaboration modes:
| Dimension | Workflow Sealing | Skill Package Sealing |
|-----------|------------------|------------------------|
| **Sealing Target** | Analysis script folder (run.py + helpers/) | Complete skill package with SKILL.md |
| **Sealing Tool** | `mgc_seal_package` | `mgc_seal_package` |
| **Recipient Usage** | `mgc_run` directly invokes entry script | AI reads SKILL.md instructions and calls corresponding scripts |
| **Use Case** | Deliver a "one-click run" analysis tool to business team | Deliver a complete "AI-understandable usage guide" package to client |
| **SKILL.md Included?** | Not required | Required (recipient AI's usage manual) |
| **Recipient AI Visibility** | Sees only run status | Can read SKILL.md (plaintext), but cannot see script source code |
> **Selection guidance**:
> - If the recipient only needs to "execute your analysis", use **Workflow Sealing**
> - If the recipient needs AI to autonomously call different scripts per your package, use **Skill Package Sealing**
---
# 3. End-to-End Collaboration Flow
## 3.1 Complete Flow
```
Author Node Recipient Node (Client / Team)
─────────── ──────────────────────
1. Save workflow / skill package
mgc_save_file(path="./my_workflow")
→ MGC auto-recognizes import / subprocess relationships
2. Recipient fetches their own public key mgc_get(info_type="__NODE_PUB__",
(Public key is not secret; any channel OK) info_owner="__NODE_PUB__")
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zkeviny/skills/mgc-database-security",
"sourceUrl": "https://clawhub.ai/zkeviny/skills/mgc-database-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:39:11.403Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T16:39:11.403Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceUrl": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:39:11.403Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.3.0",
"href": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceUrl": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T03:41:25.591Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.3.0",
"description": "Version 1.3.0 introduces major upgrades for secure, zero-exposure workflow management and collaboration. - Upgraded to MGC Blackbox 1.5.2+; added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging). - Migrated script management from single-script to workflow-folder mode with import, from-import, relative-path, and subprocess auto-recognition. - Credential management unified 'info_type' naming from 'credential' to 'token' for skill_spec consistency. - Added dedicated documentation for workflow/skill-package sealed-collaboration. - Enhanced agent prompt: workflow examples upgraded from multi-step chain to find → save_file → run pattern. - Expanded tooling: now documents 10 MCP tools including mgc_save_file, mgc_seal_package, mgc_package.",
"href": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceUrl": "https://clawhub.ai/zkeviny/mgc-database-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T03:41:25.591Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
