Start here
The safe first move
Wrap any raw SQL string passed to execute() in text() from sqlalchemy.
Stop before automation when: Dynamic SQL construction that mixes strings and expressions. Helpers that reshape SQL arguments before execution.
Target shape
from sqlalchemy import text
result = conn.execute(text("SELECT * FROM users WHERE id = :id"), {"id": 1})