Use paramterized queries which is the safety mechanism provided by your database itself.
See https://www.prisma.io/docs/orm/prisma-client/using-raw-sql/raw-queries#parameterized-queries