The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Sqlsure listing page.
AI writes your SQL. sqlsure makes sure it's right.
A query can be perfectly valid, run without error, and return a number that's silently wrong — revenue double-counted by a join, an average summed, a patient identifier exposed. Databases don't catch this. Linters don't catch this. LLMs reviewing their own SQL don't catch this.
sqlsure does — deterministically, in 0.1 ms, before the query runs.
Proof, not promises: we ran sqlsure over the gold answers of the two benchmarks every text-to-SQL model is graded on. 2,568 expert-written queries, 45 flags, zero false alarms — including a BIRD dev gold answer that is provably wrong by 8× from the exact bug class sqlsure targets, and a schema defect now filed upstream.
sqlsure judges SQL against facts your team already declared — dbt unique
tests become grain, relationships tests become join cardinality, one-line
meta tags mark what's safe to sum. No new language to learn, no model to
maintain by hand. Rules are dictionary lookups, not LLM calls: same input,
same verdict, every time, offline.
Every rejection carries a machine-actionable fix, so AI agents
self-repair: draft → check → fix → check → execute. In our benchmark,
applying the fix verbatim produced a passing query 10/10 times.
Or clone and run the 30-second demo:
1. CI gate — blocks the merge when a PR double-counts:
2. MCP server — your AI agent must pass inspection before executing:
See docs/MCP.md for tool reference and agent-loop patterns.
3. Library — embed check() inside any text-to-SQL product or agent
framework. A drop-in SemanticGate wraps
Vanna/WrenAI-style generators; a
semantic eval metric scores NL2SQL output
where execution-accuracy is blind.
Also available as an Agent Skill — a single SKILL.md your agent loads directly; no server process needed.
| Rule | Severity | Catches |
|---|---|---|
| FANOUT | error | SUM/COUNT of additive measure after one-to-many join |
| CHASM | error | two+ fan-out joins multiplying each other |
| ADDITIVITY | error | SUM of a non-additive measure (rates, averages) |
| SEMI_ADDITIVE | error | balances/censuses summed across their snapshot dimension |
| JOIN_KEY | error | join on columns matching no declared relationship |
| CROSS_JOIN | error | join with no predicate |
| WEIGHTED_AVG | warning | AVG silently re-weighted by fan-out |
| UNDECLARED_JOIN | warning | join with no declared relationship (unverifiable ≠ safe) |
| SENSITIVE_COLUMN | policy | PHI/PII column exposed in query output |
When sqlsure can't verify something, it says "can't verify" — never "looks fine." Honest uncertainty is a feature.
dbt (works today): manifest.json or schema.yml — the tests teams
already wrote become enforceable semantics, zero config
Plain PK/FK declarations (works today — powered the benchmark audits)
The live database itself (works today): no semantic layer at all?
sqlsure.introspect builds the rulebook from the catalog — SQLite
PRAGMAs or information_schema PK/FK (postgres/mysql). Introspecting
BIRD's own database files recovered 2 foreign keys missing from the
benchmark's published schema
(bird-bench/mini_dev#37)
Hand-written JSON — model.example.json
OSI and WrenAI MDL (working loaders in
integrations/): OSI
demonstrated on the spec's published examples;
WrenAI MDL demonstrated on WrenAI's own
shipped example manifest — primaryKey → grain, relationship
joinType + condition → join edges, cube measures → additivity
Cube, Snowflake Semantic Views — adapters on the roadmap; the
engine only ever sees one SemanticModel
Apache-2.0 · sqlsure.ai
mcp-name: io.github.sqlsure/sqlsure