Letting a model write SQL against a real database needs two locks. The guard parses every query and stops anything but a single read-only query, unknown tables and columns, withheld personal data and runaway plans, and says why; the sandbox runs what passes on a read-only connection. Below: the guard's decision on each of 20 legitimate queries and 40 attacks.
Each attack is something a prompt-injected or careless model could write. The sandbox column is what a read-only connection alone would have done with it.
Schema and policy
Hallucinated schema, on Spider
A model's predictions for Spider's dev questions, and the gold queries with one column swapped for a plausible name that does not exist.