Beware, DuckDB SQL can read files. I don't think there's any access control there. Feeding it SQL given to you over the network might not be what you want; it's intended for local use.
You can disable file access: https://duckdb.org/docs/operations_manual/securing_duckdb/ov...