CAIN-42 CAIN Studio

Recipes

Guard sql

For an agent with database access, in 15 frameworks.

Last reviewed 2026-10-03

Reads run; dropping a table is refused outright. Text is compared after normalising case, whitespace, SQL comments and look-alike characters, so DROP/**/table and full-width letters are caught too. Add one rule per statement you never want (truncate, alter, grant).

The rule

{
  "name": "sql-guard",
  "effect": "deny",
  "priority": 10,
  "match_path": "/tools/run_sql",
  "conditions": [
    {
      "field": "query",
      "op": "matches",
      "value": "*drop table*"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"query": "DROP TABLE customers"}
Safe{"query": "SELECT id FROM customers LIMIT 10"}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)run_sqlthe function that acts
LangChainrun_sqlyour agent's tool list
LangGraphrun_sqlthe tools your graph's nodes call
OpenAI Agents SDKrun_sqlfunction tools
CrewAIrun_sqlCrewAI's before-tool-call hooks
LlamaIndexrun_sqlFunctionTool
Pydantic AIrun_sqlan agent capability
AutoGen (agentchat)run_sqlthe callables you give AssistantAgent
Google ADKrun_sqlthe functions in an agent's tools
Claude Agent SDKmcp__ops__run_sqlPreToolUse hooks
MCP client (Python)run_sqlany MCP client session
OpenTelemetryrun_sqlyour existing tracing
Any other frameworkrun_sqlany Python callable
TypeScript / JavaScriptrun_sqlany async function
HTTP (any language)run_sqlyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem