``` Col(`id", (DELETE FROM foo) AS "bar`) // becomes SELECT "id", (DELETE FROM foo) AS "bar" FROM ... ``` sql injection should be avoided by matching col name against regexp