TaskHub defense in depth for an AI database agent
A diagram showing a traditional human review workflow before MCP and the layered defense-in-depth model used in the TaskHub lab.
TaskHub: Defense in Depth for an AI Database Agent
Each layer limits a different failure mode; no single layer is treated as the complete security boundary.
BEFORE MCP · TRADITIONAL WORKFLOW
User
AI generates SQL
Human reviews
Oracle Database
The lab changes this model.
With SQLcl MCP, the agent can inspect the schema, apply changes, run tests, and review results.
That is useful for a POC, but it raises a design question: what still stops an unintended action?
The rest of the diagram shows the controls used in TaskHub.
1 · DEVELOPMENT ISOLATION
2 · AGENT AND TOOL CONTROLS
3 · ORACLE-ENFORCED AUTHORIZATION
4 · APPLICATION DATA ACCESS
Local Docker Lab
Oracle Database + ORDS are isolated from a shared development database · Limits blast radius
Task Contract
Prompt · scope · constraints
SQLcl MCP
Defined tools · restrict level
Approval Gate
Human approval when configured
Saved Connection
Selects the database identity
Oracle Identity
OWNER · API · APP
Oracle Privileges
Enforce what the identity can do
API Packages
Controlled writes
Filtered Views
Controlled reads