Recipes
Guard sql
For an agent with database access, in 15 frameworks.
Last reviewed 2026-10-03
Reads run; dropping a table is refused outright. Text is compared after normalising case, whitespace, SQL comments and look-alike characters, so DROP/**/table and full-width letters are caught too. Add one rule per statement you never want (truncate, alter, grant).
The rule
{
"name": "sql-guard",
"effect": "deny",
"priority": 10,
"match_path": "/tools/run_sql",
"conditions": [
{
"field": "query",
"op": "matches",
"value": "*drop table*"
}
]
}Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.
| Risky | {"query": "DROP TABLE customers"} |
|---|---|
| Safe | {"query": "SELECT id FROM customers LIMIT 10"} |
Pick your framework
| Framework | Tool name CAIN sees | Plugs into |
|---|---|---|
| Python (any function) | run_sql | the function that acts |
| LangChain | run_sql | your agent's tool list |
| LangGraph | run_sql | the tools your graph's nodes call |
| OpenAI Agents SDK | run_sql | function tools |
| CrewAI | run_sql | CrewAI's before-tool-call hooks |
| LlamaIndex | run_sql | FunctionTool |
| Pydantic AI | run_sql | an agent capability |
| AutoGen (agentchat) | run_sql | the callables you give AssistantAgent |
| Google ADK | run_sql | the functions in an agent's tools |
| Claude Agent SDK | mcp__ops__run_sql | PreToolUse hooks |
| MCP client (Python) | run_sql | any MCP client session |
| OpenTelemetry | run_sql | your existing tracing |
| Any other framework | run_sql | any Python callable |
| TypeScript / JavaScript | run_sql | any async function |
| HTTP (any language) | run_sql | your own call site |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem