Overview
This tool is used to convert natural language to SQL queries. When passed to the agent it will generate queries and then use them to interact with the database. This enables multiple workflows like having an Agent to access the database fetch information based on the goal and then use the information to generate a response, report or any other output. Along with that provides the ability for the Agent to update the database based on its goal. Attention: By default the tool is read-only (SELECT/SHOW/DESCRIBE/EXPLAIN only). Write operations requireallow_dml=True or the CREWAI_NL2SQL_ALLOW_DML=true environment variable. When write access is enabled, make sure the Agent uses a scoped database user or a read replica where possible.
Security Model
NL2SQLTool is an execution-capable tool. It runs model-generated SQL directly against the configured database connection.
This means risk depends on your deployment choices:
- Which credentials you provide in
db_uri - Whether untrusted input can influence prompts
- Whether you add tool-call guardrails before execution
Hardening Recommendations
Use all of the following in production:- Use a read-only database user whenever possible
- Prefer a read replica for analytics/retrieval workloads
- Grant least privilege (no superuser/admin roles, no file/system-level capabilities)
- Apply database-side resource limits (statement timeout, lock timeout, cost/row limits)
- Add
before_tool_callhooks to enforce allowed query patterns - Enable query logging and alerting for destructive statements
Read-Only Mode & DML Configuration
NL2SQLTool operates in read-only mode by default. Only the following statement types are permitted without additional configuration:
SELECTSHOWDESCRIBEEXPLAIN
INSERT, UPDATE, DELETE, DROP, CREATE, ALTER, TRUNCATE, etc.) will raise an error unless DML is explicitly enabled.
Multi-statement queries containing semicolons (e.g. SELECT 1; DROP TABLE users) are also blocked in read-only mode to prevent injection attacks.
Enabling Write Operations
You can enable DML (Data Manipulation Language) in two ways: Option 1 — constructor parameter:Usage Examples
Read-only (default) — safe for analytics and reporting:Requirements
- SqlAlchemy
- Any DB compatible library (e.g. psycopg2, mysql-connector-python)
Installation
Install the crewai_tools packageUsage
In order to use the NL2SQLTool, you need to pass the database URI to the tool. The URI should be in the formatdialect+driver://username:password@host:port/database.
Code
