GoSQLX

Infrastructure · tested 2026-09-27 · by the Hlido desk, not the vendor

In short: A fast, well-presented multi-dialect SQL parsing SDK for Go with a genuinely agent-first MCP surface — but its headline performance and traction numbers are vendor-asserted and, in one case, don't reconcile.

5 PASS · 0 FAIL of 5 public-surface claims

Quick answer

GoSQLX scores 75/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-27). STEADY (75) because the product is coherent, actively presented, open-source (Apache-2.0), and offers a real, keyless agent-integration path via MCP alongside a working in-page playground that demonstrated the core parse Pricing: Open source (free entry point documented).

GoSQLX is a developer library, not an AI product, yet it earns its place in an agent register: it ships a keyless, no-install remote MCP server (mcp.gosqlx.dev) exposing seven SQL tools — parse, format, validate, lint, analyze, injection-detect, list-dialects — to Claude, Cursor, or any MCP client, which is exactly the kind of narrow, composable capability agents can consume without ceremony. The public surface is strong: the in-page playground actually parsed a multi-table JOIN into a full AST during our capture, so the core function is demonstrable rather than merely claimed, and the project spreads across a Go SDK, CLI, VS Code extension, GitHub Lint Action, and WASM under Apache-2.0. Where it should be read with caution is the numbers. The marquee throughput figure (1.38M ops/sec, sub-microsecond latency) and the chart beating vitess and pg_query are self-reported benchmarks on the author's own Apple M4 hardware, and the dialect-coverage percentages are self-graded QA. More pointedly, the homepage advertises "1.2k GitHub Stars" while Hlido's scout recorded 111 stars for the same repository — a gap the public surface does not explain. None of this makes GoSQLX a weak tool; the design is coherent and the agent path is real. It does mean the performance and popularity claims are inputs to verify, not conclusions to trust, and Hlido ran no hands-on behavioral test of the MCP tools or SDK.

Why STEADY

STEADY (75) because the product is coherent, actively presented, open-source (Apache-2.0), and offers a real, keyless agent-integration path via MCP alongside a working in-page playground that demonstrated the core parse function. It is held below the top band because the review is a public-surface (medium-confidence) assessment with no hands-on behavioral run, every performance and coverage figure is vendor self-reported, and the homepage's advertised star count (1.2k) does not reconcile with the 111 stars Hlido's scout recorded — a traction discrepancy a buyer must resolve independently. VITAL is unreachable without hands-on behavioral testing Hlido did not perform.

Public-surface checklist

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-79cf746840c262b9-gosqlx-dev). Our own captures — not vendor marketing material.

GoSQLX — run screenshot 1 (home.png)
home.png
GoSQLX — run screenshot 2 (page__main-content.png)
page__main-content.png
GoSQLX — run screenshot 3 (page_.png)
page_.png
GoSQLX — run screenshot 4 (page_docs_.png)
page_docs_.png

What it does well

What it fails at

Red flags

Best for

  • Go developers who need an embeddable, multi-dialect SQL parser, formatter, and linter
  • Agent builders who want SQL parsing, validation, and injection-detection tools available over MCP without provisioning an API key
  • Teams building SQL tooling — linters, analyzers, IDE integrations — on top of a shared AST
  • Workflows that need SQL security scanning (injection detection with severity classification) as a component

Not recommended for

  • Teams that require independently reproduced performance benchmarks before adoption
  • Non-Go stacks needing a native library (the MCP server and WASM build only partially bridge this)
  • Buyers who treat published star/traction counts as a due-diligence signal — the figures here do not reconcile
  • Production use where correctness must be verified by hands-on testing rather than vendor QA claims

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-28.

Related agents

Agent relevance

API CLI MCP SDK Behavioral-testable

Primary agent path is a keyless, no-install remote MCP server (https://mcp.gosqlx.dev/mcp) exposing 7 SQL tools (parse_sql, format_sql, validate_sql, lint_sql, analyze_sql, detect_injection, list_dialects) consumable by Claude, Cursor, or any MCP client. Beyond MCP, GoSQLX ships as a Go SDK (github.com/ajitpratap0/GoSQLX), a CLI, a VS Code extension, a GitHub Lint Action, and a WASM build, plus an interactive web playground. It is a developer library rather than an AI product, but the MCP surface makes its parsing/validation/injection-detection capabilities directly agent-consumable.

Agent-friendly score: 8/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-2+editorial-narrative-v2 · Methodology version 2026.09 ·

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/ajitpratap0-gosqlx.svg)](https://hlido.eu/check/?agent=ajitpratap0-gosqlx)

HTML

<a href="https://hlido.eu/check/?agent=ajitpratap0-gosqlx"><img src="https://hlido.eu/badge/ajitpratap0-gosqlx.svg" alt="Hlido trust score"></a>