$npx skillfedfor your agent

vanna

Generate SQL queries from natural language

With conditionsPyPI Front-EndsReleased Feb 2026265.7K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — vanna-2.0.2-py3-none-any.whl
v2.0.2 · released 2026-02-02 · Python >=3.9 · 10 runtime deps: pydantic, click, pandas, httpx, PyYAML, plotly, tabulate, sqlparse

Yes, with strong conditions. Vanna is feature-rich and well-suited for building natural-language data interfaces with enterprise security and streaming UI components. However, the repository is archived and marked abandoned, which means security patches for the two known vulnerabilities (GHSA-6mj8-jmp2-g8q7, PYSEC-2026-3397) are unlikely to be released. Install only if you can accept the security risk, have the capacity to fork and patch if needed, or plan to migrate away within a defined timeframe. For new projects requiring long-term support, consider alternatives with active maintenance.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; also requires an LLM API key (e.g., Anthropic, OpenAI) and a supported database connection.
  • Low install friction with a pure-Python wheel and no compiled dependencies.
  • However, the repository is archived and marked abandoned as of the latest commit on 2026-02-02, raising concerns about future maintenance and security updates despite recent release activity.

License · maintenance · safety

permissive license (permissive) — MIT license (permissive) means you can use, modify, and distribute Vanna freely in commercial and private projects with minimal restrictions, though you must include the license notice.

last release 2026-02-02 (193 days) · last repo commit 2026-02-02 · 23,826 stars · archived

2 known vulnerabilities (OSV.dev, 2026-08-14) · 265,694 downloads/mo, #8,317 on PyPI

Verify before relying

pip install vanna

from vanna import Agent
from vanna.integrations.anthropic import AnthropicLlmService
from vanna.tools import RunSqlTool
from vanna.integrations.sqlite import SqliteRunner

llm = AnthropicLlmService(model="claude-sonnet-4-5")
agent = Agent(llm_service=llm)
agent.tool_registry.register(RunSqlTool(sql_runner=SqliteRunner("data.db")))
# Query via agent.chat("Show Q4 sales")
  • Whether the archived repository status means security patches will still be released for the two known vulnerabilities (GHSA-6mj8-jmp2-g8q7, PYSEC-2026-3397).
  • Whether the 10 runtime dependencies (pydantic, click, pandas, httpx, PyYAML, plotly, tabulate, sqlparse, sqlalchemy, requests) introduce any transitive vulnerabilities or breaking changes.
  • Whether the streaming and enterprise features (row-level security, audit logs, rate limiting) are fully production-tested or still experimental.
Same gist for agents: .md · .json

What it is and what it does

Vanna is a Python framework that bridges natural language and SQL by using an LLM to translate user questions into database queries, execute them, and return results as interactive visualizations and summaries. It ships with a pre-built web component (`<vanna-chat>`) that can be embedded in any webpage and handles authentication via your existing cookies or JWT tokens.

The package is designed for multi-tenant and enterprise use cases, with built-in support for user-aware permissions, row-level security filtering, audit logging, and streaming responses. It integrates with any LLM (OpenAI, Anthropic, Ollama, etc.) and any SQL database (PostgreSQL, MySQL, Snowflake, BigQuery, SQLite, etc.), and provides extension points for custom tools, lifecycle hooks, and observability. However, the repository is archived and abandoned, which may affect long-term support and security maintenance.

Use it for

  • Build a natural-language analytics dashboard where non-technical users ask questions and get instant SQL results, tables, and charts without writing queries.
  • Add a multi-tenant chat interface to a SaaS product with automatic row-level security filtering so each user sees only their permitted data.
  • Embed a pre-built web component in an existing web app to enable conversational data exploration without building a custom chat UI.
  • Implement audit logging and rate limiting per user for compliance and cost control in enterprise data access scenarios.
  • Extend Vanna with custom tools (e.g., email, Slack notifications) to create an agentic workflow that answers questions and takes actions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with strong conditions.

Vanna is feature-rich and well-suited for building natural-language data interfaces with enterprise security and streaming UI components. However, the repository is archived and marked abandoned, which means security patches for the two known vulnerabilities (GHSA-6mj8-jmp2-g8q7, PYSEC-2026-3397) are unlikely to be released. Install only if you can accept the security risk, have the capacity to fork and patch if needed, or plan to migrate away within a defined timeframe. For new projects requiring long-term support, consider alternatives with active maintenance.

Install

vanna on PyPI

Before you install

Low install friction with a pure-Python wheel and no compiled dependencies. However, the repository is archived and marked abandoned as of the latest commit on 2026-02-02, raising concerns about future maintenance and security updates despite recent release activity.

Requires Python 3.9 or later; also requires an LLM API key (e.g., Anthropic, OpenAI) and a supported database connection.

License in practice

MIT license (permissive) means you can use, modify, and distribute Vanna freely in commercial and private projects with minimal restrictions, though you must include the license notice.

Quickstart

pip install vanna

from vanna import Agent
from vanna.integrations.anthropic import AnthropicLlmService
from vanna.tools import RunSqlTool
from vanna.integrations.sqlite import SqliteRunner

llm = AnthropicLlmService(model="claude-sonnet-4-5")
agent = Agent(llm_service=llm)
agent.tool_registry.register(RunSqlTool(sql_runner=SqliteRunner("data.db")))
# Query via agent.chat("Show Q4 sales")

Verify before relying

  • Whether the archived repository status means security patches will still be released for the two known vulnerabilities (GHSA-6mj8-jmp2-g8q7, PYSEC-2026-3397).
  • Whether the 10 runtime dependencies (pydantic, click, pandas, httpx, PyYAML, plotly, tabulate, sqlparse, sqlalchemy, requests) introduce any transitive vulnerabilities or breaking changes.
  • Whether the streaming and enterprise features (row-level security, audit logs, rate limiting) are fully production-tested or still experimental.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
10 packages
pydanticclickpandashttpxPyYAMLplotlytabulatesqlparsesqlalchemyrequests
MaintenanceAbandoned 193 days since the last release
Last repo commit repository archived
First released
Downloads265,694 / month, #8,317 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilities2 GHSA-6mj8-jmp2-g8q7, PYSEC-2026-3397
Classifiers
License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3

Evidence: vanna-2.0.2-py3-none-any.whl

Tags

Capabilities
natural language to SQLtext to database queryAI SQL generationquestion answering databaseLLM database interfacestreaming SQL resultsuser-aware data queries
Topics
llm-sql-bridgemulti-tenantstreaming-ui

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “natural language to SQL”

  • vannaVanna converts natural language questions into SQL queries and…
  • pandasaiPandasAI lets you ask questions about your data in natural language…
  • pandasai-litellmIntegrates LiteLLM with PandasAI to enable natural-language queries…

Give your agent the search over MCP, or paste the wish link into any chat.

More Front-Ends packages

SQLAlchemy Worth it
PyPI · Front-Ends · released Aug 2026

SQLAlchemy is a Python SQL toolkit and Object Relational Mapper (ORM) that provides both a high-level ORM layer for declarative object persistence and a Core SQL construction system for direct database abstraction and query building.

permissive licensepure Python · 3.7+
422.7Mdownloads / mo
psycopg2-binary Worth it
PyPI · Software Development · released Apr 2026

psycopg2-binary is a PostgreSQL database adapter for Python that implements the DB API 2.0 specification, enabling Python applications to connect to and query PostgreSQL databases with thread-safe concurrent operations.

copyleftcompiled wheel · 3.9+
271.6Mdownloads / mo
alembic Worth it
PyPI · Front-Ends · released Aug 2026

Alembic generates and manages database schema migrations for SQLAlchemy applications, handling version control of database structure changes with support for upgrades, downgrades, and auto-generation from model changes.

Install it if you use SQLAlchemy and need to version-control schema changes; skip it only if you manage migrations manually or use a different ORM entirely.

MITpure Python · 3.10+
215.2Mdownloads / mo
weaviate-client Worth it
PyPI · Front-Ends · released Aug 2026

A Python client library for connecting to and querying Weaviate, a vector database that enables semantic search and AI-powered data retrieval.

permissive licensepure Python · 3.10+
213.2Mdownloads / mo
databricks-sql-connector Worth it
PyPI · Front-Ends · released Jul 2026

A Python client library that connects to Databricks clusters and SQL warehouses using a Thrift-based protocol, conforming to the Python DB API 2.0 specification and supporting Arrow-based data exchange.

Install it if you need to query Databricks clusters or SQL warehouses from Python.

Apache-2.0pure Python
119.5Mdownloads / mo
psycopg Worth it
PyPI · Software Development · released May 2026

Psycopg 3 is a PostgreSQL database adapter for Python that enables applications to connect to, query, and manage PostgreSQL databases using Python code.

Install it if you need to connect Python to PostgreSQL.

LGPL-3.0-onlypure Python · 3.10+
117.0Mdownloads / mo

See also pandasai · apache-superset · assistant-stream · moz-sql-parser · pandasai-litellm · django-sql-explorer · mo-sql-parsing · omnigent-ui-sdk · instructor · mlflow