AI agents
curral is a good fit for AI agents: the agent gets its own credential, the policy bounds what it can do, and every query lands in the audit log.
/v1/schemalists only what the agent may query, with masked columns and filtered tables flagged.dry_runlets the agent check a query against the policy before running it.- Row limits and timeouts per role keep exploratory queries cheap.
- Clear errors: 403 says the policy refused, 429 says slow down, and the row-limit trailer says the result is incomplete.
The agent skill
Section titled “The agent skill”skills/curral
is an agent skill that teaches an assistant to discover the schema, validate
with dry_run, and query within its permissions. It ships with a shell
helper:
scripts/curral.sh schema # everything you can readscripts/curral.sh schema table=monthly_revenuescripts/curral.sh query "SELECT count(*) AS n FROM monthly_revenue"scripts/curral.sh query -m 20 "SELECT * FROM monthly_revenue" # at most 20 rowsscripts/curral.sh dry-run "SELECT ..."| Exit code | |
|---|---|
| 0 | ok |
| 1 | HTTP or network error |
| 2 | incorrect usage |
| 3 | result truncated by the row limit |
| 4 | error in the middle of the result |