Back to News
RSS feedgithub.com

Schema-guard blocks AI agents from writing SQL against nonexistent schema objects

Summary

schema-guard is an open-source developer tool that prevents AI coding agents from using table and column names that are absent from a repository-held database schema snapshot. It can inspect SQL before execution or file creation through a Claude Code hook, MCP server, pre-commit hook, or CI check, while supporting sources including dbt, DuckDB, SQLite, BigQuery, Snowflake, Databricks, database URLs, DDL, and CSV exports. In an evaluation using four requests, three runs, and two Claude Code model arms, neither Haiku 4.5 nor Sonnet 5 produced a working file without the snapshot; with the snapshot, all 48 generated files ran successfully. The reported mistakes in the remaining two cases were date-logic errors rather than nonexistent names. The hook denied Haiku on 10 of 12 runs and the model corrected the SQL on its first retry each time, while Sonnet found the snapshot without a denial. The project reports zero false blocks on 1,034 Spider queries and 960 defog SQL-eval queries, catching 1,032 and 959 planted naming errors respectively; two Spider misses occurred in correlated subqueries where the checker deliberately avoids certainty. It resolves aliases, CTEs, subqueries, dbt references, and many SQL dialects, but does not judge semantic correctness, reliably inspect dynamic SQL, or guarantee freshness when the snapshot is stale. The author cautions that the evaluation is small and synthetic, and says Snowflake and BigQuery readers have not yet been tested against live accounts.