LLM engineering · Python

Text-to-SQL Guardrails

Letting a model write SQL against a real database needs two locks. The guard parses every query and stops anything but a single read-only query, unknown tables and columns, withheld personal data and runaway plans, and says why; the sandbox runs what passes on a read-only connection. Below: the guard's decision on each of 20 legitimate queries and 40 attacks.

The guard's decision on every query

Each attack is something a prompt-injected or careless model could write. The sandbox column is what a read-only connection alone would have done with it.

Schema and policy

Hallucinated schema, on Spider

A model's predictions for Spider's dev questions, and the gold queries with one column swapped for a plausible name that does not exist.