Skip to content

AI agents

curral is a good fit for AI agents: the agent gets its own credential, the policy bounds what it can do, and every query lands in the audit log.

  • /v1/schema lists only what the agent may query, with masked columns and filtered tables flagged.
  • dry_run lets the agent check a query against the policy before running it.
  • Row limits and timeouts per role keep exploratory queries cheap.
  • Clear errors: 403 says the policy refused, 429 says slow down, and the row-limit trailer says the result is incomplete.

skills/curral is an agent skill that teaches an assistant to discover the schema, validate with dry_run, and query within its permissions. It ships with a shell helper:

Terminal window
scripts/curral.sh schema # everything you can read
scripts/curral.sh schema table=monthly_revenue
scripts/curral.sh query "SELECT count(*) AS n FROM monthly_revenue"
scripts/curral.sh query -m 20 "SELECT * FROM monthly_revenue" # at most 20 rows
scripts/curral.sh dry-run "SELECT ..."
Exit code
0 ok
1 HTTP or network error
2 incorrect usage
3 result truncated by the row limit
4 error in the middle of the result
  1. Create a role for the agent in your policy, read-only, with tight limits and masks on personal data.
  2. Generate an API key: curral gen-api-key assistant agent.
  3. Copy skills/curral into your assistant’s skills directory and set CURRAL_URL and CURRAL_TOKEN in its environment.