From a security POV creating your script in text and sending it back to the
db is very unsafe. Just ask Sony. To overcome that you are encouraged to create stored procedures, sprocs, and pass back the params for a much higher level of security.
This is a bare-bones starter on sprocs for anyone who is interested.
https://www.mssqltips.com/sqlservertutorial/168/different-options-for-creati...