matimo-postgres
PostgreSQL tools for Matimo - execute SQL queries safely with policy-gated approval.
Installation
pip install matimo matimo-postgres
Available Tools (1 Tool)
| Tool | Description |
|---|---|
postgres-execute-sql |
Execute a SQL query against a PostgreSQL database |
The tool does not set requires_approval itself - if you want destructive operations
(INSERT, UPDATE, DELETE, DROP) to require human approval, gate them yourself via a
policy file or a custom
PolicyEngine.
Quick Start
import asyncio
from matimo import Matimo
from matimo_postgres import get_tools_path
async def main():
matimo = await Matimo.init(get_tools_path())
# Run a SELECT query
result = await matimo.execute('postgres-execute-sql', {
'sql': 'SELECT id, name FROM users LIMIT 10',
})
print(result)
asyncio.run(main())
With Interactive Approval (Recommended for Writes)
If you've configured a policy that quarantines this tool for HITL review, provide an
on_hitl callback:
async def ask_user(request) -> dict:
print(f"\nSQL requires approval:\n{request.params.get('sql')}")
answer = input("Run this query? [y/n]: ").strip()
return {'approved': answer == 'y', 'reason': 'user reviewed'}
matimo = await Matimo.init(get_tools_path(), on_hitl=ask_user)
# This will prompt before executing, if quarantined by your policy
await matimo.execute('postgres-execute-sql', {
'sql': 'DELETE FROM sessions WHERE expired_at < NOW()',
})
Authentication
export MATIMO_POSTGRES_URL="postgresql://user:password@localhost:5432/mydb"
# or individual params
export MATIMO_POSTGRES_HOST="localhost"
export MATIMO_POSTGRES_PORT="5432"
export MATIMO_POSTGRES_DB="mydb"
export MATIMO_POSTGRES_USER="myuser"
export MATIMO_POSTGRES_PASSWORD="mypassword"
Security Notes
- All SQL queries go through Matimo's content validator - SSRF and injection patterns are detected
- The tool itself does not require approval - use a policy file if you want writes gated
- Use a read-only database user for agent workloads when possible
- Consider a policy file to restrict allowed SQL patterns
Documentation
Links
Release files for matimo-postgres 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| matimo_postgres-0.1.3.tar.gz | 4.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| matimo_postgres-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 10.0 kB
Release files / matimo_postgres-0.1.3.tar.gz
| Download URL | matimo_postgres-0.1.3.tar.gz |
|---|---|
| Size | 4.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
078f31274c596c550c2b02f50f8385cdc4bbbc332e121455147d2faca0d23623
|
|
BLAKE2b-256 checksum How to use checksums |
0a59c7a380aaed3dabdec14b2a0b673d59c1ec902bc9976abda6b5aaf8ba2a8a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / matimo_postgres-0.1.3-py3-none-any.whl
| Download URL | matimo_postgres-0.1.3-py3-none-any.whl |
|---|---|
| Size | 5.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
891e5e1d0dde00340a5a8c7c0f5d4d3b164784d1c6cc0cf451e86ec0e22d4d94
|
|
BLAKE2b-256 checksum How to use checksums |
6eeef0862efc34930a12066abd609f15f505071b916a205fb76c744a9098ee71
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|