safe-sql-execution - Safely execute SQL against user databases
Guides safe SQL construction, provenance tracking, sanitization, and execution against a user's Postgres database.
Tags
Updated: 2026-10-02Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Classify SQL fragment provenance
- Sanitize identifiers and literals
- Track trusted SQL types
- Require explicit execution actions
- Execute only safe fragments
Inputs
- SQL fragments
- External input values
- User-authored SQL
- Database-derived SQL
- Explicit user actions
- Postgres database
Outputs
- SafeSqlFragment values
- UntrustedSqlFragment values
- Executed SQL statements
- Database state changes
- Compile-time type errors
Requirements
- @supabase/pg-meta utilities
- TypeScript branded types
- executeSql accepting SafeSqlFragment
- Explicit user action for promotion
- Postgres database access
