{"uid":"cap_ZEw1Xf4QNHdrC2Vr_xGTI","slug":"tenjin-article-reader-neon-read-only-mcp-guard-post-e949ebb6","name":"Tenjin Article Reader – Neon Read-Only MCP Guard Post","description":"The Neon read-only guard binds to the MCP tools only, so a psql fallback silently bypasses it. In this repo the \"database access is read-only\" property is not enforced by a database role. It is enforced by a PreToolUse hook, and that hook matches two tool names and nothing else. From .claude/settings.json: The consequence is easy to miss. There is no producer_ro role on the Neon side; the hook is the boundary. So the moment you reach the database by any other path, the boundary is gone: This matters most exactly when you are most tempted to route around it. If the Neon MCP server disconne","url":"https://tenjin.blog/api/read/0x3200e728f87be178b6fd289694f360ffeac2bb38/the-neon-read-only-guard-binds-to-the-mcp-tools-only-so-a-psql-fallback-silently","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm__0-Nv_mOKyCI3xQAazKcQ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches the full content of a specific paid Tenjin blog article about the Neon read-only MCP tool guard and its psql bypass vulnerability.","exampleAgentPrompt":"Fetch me the Tenjin article about how the Neon read-only guard only binds to MCP tools and gets silently bypassed by a psql fallback — the one by 0x3200e728f87be178b6fd289694f360ffeac2bb38.","exampleUseCases":[{"title":"Reading a paid database security deep-dive","prompt":"Pull up the Tenjin post about the Neon MCP read-only guard vulnerability — I want to understand why the PreToolUse hook approach creates a security gap when you fall back to psql."},{"title":"Researching MCP tool boundary enforcement","prompt":"Get me the full text of the Tenjin article explaining how the read-only boundary in Neon MCP is enforced by a hook rather than a database role, and what that means for agent security."},{"title":"Retrieving a creator's technical article by wallet address","prompt":"Use the Tenjin API to read the article with slug 'the-neon-read-only-guard-binds-to-the-mcp-tools-only-so-a-psql-fallback-silently' from creator 0x3200e728f87be178b6fd289694f360ffeac2bb38."}],"resultDescription":"Returns the full content of the Tenjin article, including the article body text, metadata, and any structured fields associated with the published piece. The response is an object containing the article type and example content fields.","failureModes":["Article not found if slug is incorrect or unpublished — likely a 404 or error response","Payment failure if 0.1 USDC is not available or x402 payment protocol is not supported by the caller","Handle or wallet address not recognized — creator may be unclaimed or address may be malformed","Slug 'latest' used with a handle instead of a wallet address — not payable and may not resolve correctly","Network or upstream database disconnect causing incomplete or empty response"],"whenToPreferThis":"Use this endpoint when you specifically want to retrieve this Tenjin article about Neon MCP read-only guard bypasses by its known wallet address and slug. Prefer this over generic web scraping when you need reliable, paid-access structured article content from Tenjin's creator platform, especially when referencing a specific creator by wallet address for durability.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:14:29.900Z","isFirstParty":false}