Reads your cloud database. Only reads.
ClickHouse's hosted connection ships inside this plugin, configured and inert. It reaches nothing until you sign in to ClickHouse Cloud, and that sign-in is a decision separate from installing: the reviewer works with the connection left alone.
What signing in opens up.
the tables in your cloud service, with the columns and types inside them
the rows a query returns, where the assistant writes the query itself
It reads and stops there: no row is written, no table altered, nothing dropped. What it can reach is whatever that account can reach — no more than you see when you sign in yourself.
ClickHouse's hosted server is listed separately:ClickHouse Cloud remote MCP server
https://mcp.clickhouse.cloud/mcp