Agent skill

Setup Snowflake

by ai-analyst-lab in ai-analyst-lab/ai-analyst

First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance).

MITAuto-check: notesDatabases

Install Setup Snowflake

skills CLI
$ npx skills add ai-analyst-lab/ai-analyst --skill setup-snowflake -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ai-analyst-lab/ai-analyst setup-snowflake --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/setup-snowflake .claude/skills/setup-snowflake && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setup-snowflake
GitHub stars
304
Token cost
~2k tokens
SKILL.md length
801 words
Files
1
Skills in repo
43
Repo updated
First seen
Licence
MIT

At a glance

First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance).

  • Works in 5 steps: Choose authentication and collect the… → Write credentials to .env → Register the dataset → …
  • The user says set up snowflake
  • SKILL.md covers Purpose, When to Use, Prerequisite: the driver and Step 1: Choose authentication…, plus 5 more sections
  • Calls python3, pip and bash; reaches astral.sh; needs SNOWFLAKE_PASSWORD and SNOWFLAKE_TOKEN

What it does

Setup Snowflake is an agent skill from ai-analyst-lab/ai-analyst. First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance). Prompts for every connection field, stores the approved credential in .env, registers the dataset, and VERIFIES the session is live on the warehouse before declaring success. Use when the user says "set up snowflake", "connect to snowflake", "configure the warehouse", or is routed here from /connect-data. For day-to-day remote querying after setup, use…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Data warehousing. It works with Snowflake and Model Context Protocol. The repository describes itself as: AI Product Analyst — Claude Code-powered data analysis toolkit. The licence is MIT.

When your agent uses it

  • The user says set up snowflake
  • Connect to snowflake
  • Configure the warehouse
  • Is routed here from /connect-data

Example prompts

  • “set up snowflake”
  • “connect to snowflake”
  • “configure the warehouse”
  • “/setup-snowflake”

Requirements

  • Python 3
  • A credential in SNOWFLAKE_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Choose authentication and collect the connection details
  2. Write credentials to .env
  3. Register the dataset
  4. Verify you are LIVE on Snowflake (hard gate)
  5. Explore and hand off

What it can do on your machine

Read from SKILL.md and the folder at commit 52c0744. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • pip
    • bash
    • curl
    • sh
    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • astral.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SNOWFLAKE_PASSWORD
    • SNOWFLAKE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setup Snowflake loads about 2k tokens when it runs. Until then it costs about 160 tokens; SKILL.md has 801 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~160
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:6
    field, stores the approved credential in .env, registers the dataset, and VERIFIES the session is live on
  • NoteMentions a .env fileSKILL.md:53
    o place the approved secret directly in `.env`:
  • NoteMentions a .env fileSKILL.md:61
    ## Step 2: Write credentials to `.env`
  • NoteMentions a .env fileSKILL.md:62
    Read any existing `.env` first and preserve other variables. Then set (Write/Edit tool only):
  • NoteMentions a .env fileSKILL.md:69
    `.env`. Account, user, warehouse, database, schema, and role are not secrets and go in the dataset
  • NoteMentions a .env fileSKILL.md:85
    SNOWFLAKE_TOKEN"         # expanded from .env at connect time
  • NotePipes a well-known installer script into a shellSKILL.md:141
    1. Install `uv`: `curl -LsSf https://astral.sh/uv/install.sh | sh`, then `~/.local/bin/uvx --version`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ai-analyst-lab/ai-analyst at commit 52c0744, republished under its MIT licence (© ai-analyst-lab). 801 words, ~1,974 tokens.

Download SKILL.mdSave it as .claude/skills/setup-snowflake/SKILL.md (or your agent's skills folder).
name
setup-snowflake
description
First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance). Prompts for every connection field, stores the approved credential in .env, registers the dataset, and VERIFIES the session is live on the warehouse before declaring success. Use when the user says "set up snowflake", "connect to snowflake", "configure the warehouse", or is routed here from /connect-data. For day-to-day remote querying after setup, use connect-snowflake. An optional Snowflake MCP server (for interactive ad-hoc queries) is covered in the appendix.

Skill: Setup Snowflake

Purpose

Guided first-time Snowflake setup for the native ConnectionManager path — the connection the AI Analyst uses for every query, so every result is traced and logged. This wizard collects the connection details, stores credentials safely, registers the dataset, and then proves the session is actually on the warehouse (not the local practice copy) before it will report success.

This is deliberately native-first. The MCP server (snowflake-labs-mcp via uvx) is a separate, optional tool for interactive ad-hoc queries and is kept in the Appendix. The analyst does not query through the MCP, so setting up only the MCP leaves the analyst unconnected. Set up the native path first.

When to Use

  • /setup-snowflake, "set up snowflake", "connect to snowflake", "I have a snowflake account"
  • Routed here from /connect-data when the user selects Snowflake

Prerequisite: the driver

The native path needs snowflake-connector-python. Check it and install if missing:

bash
python3 -c "import snowflake.connector; print('driver OK')" || pip install snowflake-connector-python

(It also ships in the warehouses extra: pip install -e ".[warehouses]".)

Step 1: Choose authentication and collect the connection details

The repo ships blank, so ask for every field, one question at a time. In a class the instructor will read these out; leave each empty until the user gives it. Collect:

  1. Authentication method — recommend programmatic_access_token for service and agent users. Keep password only for accounts that still permit it. Do not imply that a service user can solve password deprecation with MFA.
  2. Account identifier — e.g. ORGNAME-ACCOUNTNAME (Snowsight: your name, bottom-left, then Account, then View account details).
  3. Username
  4. Warehouse — the compute warehouse to run on (e.g. ANALYST_WH).
  5. Database
  6. Schema — default PUBLIC if they do not say.
  7. Role — optional; skip if they do not use one.
  8. A short dataset name for this connection (used as the dataset id, lowercase-hyphen).

Then ask the user to place the approved secret directly in .env:

  • PAT: SNOWFLAKE_TOKEN
  • Password: SNOWFLAKE_PASSWORD

Credential security (non-negotiable):

  • Never echo, print, or log a token or password; never pass it as a CLI arg (visible in ps).
  • Write secrets only with the Write/Edit tool, never bash echo/cat.

Step 2: Write credentials to .env

Read any existing .env first and preserve other variables. Then set (Write/Edit tool only):

SNOWFLAKE_AUTHENTICATOR=programmatic_access_token
SNOWFLAKE_TOKEN=<programmatic-access-token>

For the legacy password path, use SNOWFLAKE_AUTHENTICATOR=password and SNOWFLAKE_PASSWORD=<password> instead. The token or password is the one secret that must live in .env. Account, user, warehouse, database, schema, and role are not secrets and go in the dataset manifest below (which is gitignored). Confirm only that the credential is present. Never print it.

Step 3: Register the dataset

Create .knowledge/datasets/{id}/ and write manifest.yaml from connection_templates/snowflake.yaml.example, filling the connection block and referencing the password by env var:

yaml
connection:
  type: snowflake
  authenticator: programmatic_access_token
  account: "<account>"
  warehouse: "<warehouse>"
  database: "<database>"
  schema: "<schema>"
  user: "<username>"
  token: "$SNOWFLAKE_TOKEN"         # expanded from .env at connect time
  # role: "<role>"                  # include only if given

For legacy password authentication, set authenticator: password and replace token with password: "$SNOWFLAKE_PASSWORD". Also create an empty quirks.md and metrics/index.yaml, and point .knowledge/active.yaml at this dataset with the remote opt-in on:

yaml
active_dataset: "{id}"
use_remote: true
Show full SKILL.md (353 more words)Show less

Step 4: Verify you are LIVE on Snowflake (hard gate)

Connect through ConnectionManager and confirm the session is really on the warehouse, not the local DuckDB fallback. Run:

bash
AAP_USE_REMOTE=1 python3 - <<'PY'
from helpers.data.connection_manager import ConnectionManager
cm = ConnectionManager(dataset_id="{id}")
cm.connect()
print(cm.test_connection()["message"])          # -> "Live on account ..., warehouse ..."
v = cm.verify_remote()                            # proves snowflake, not the local fallback
assert v["remote"], f"NOT LIVE: {v['reason']}"
print("Tables:", cm.list_tables()[:25])
PY
  • v["remote"] is True → show the account, warehouse, database.schema, and the table list as proof, then go to Step 5.
  • v["remote"] is False → do NOT declare success. The reason tells you what to fix:
    • "resolved to 'duckdb'/'csv', not snowflake" → the remote opt-in did not take. Make sure AAP_USE_REMOTE=1 is in the same shell command as python3, and use_remote: true is in active.yaml.
    • "not installed" → install snowflake-connector-python (Prerequisite above).
    • an auth/account error → re-check the method and offending field (Step 1). Common: wrong account identifier format, expired PAT, PAT_INVALID, a PAT policy that still requires a network policy, password typo, warehouse suspended, or account not activated.

Never report "connected" on the strength of the manifest file existing. Success means verify_remote() returned True.

Step 5: Explore and hand off

With the connection verified, show what is there and suggest a first question:

bash
AAP_USE_REMOTE=1 python3 -c "from helpers.data.connection_manager import ConnectionManager as C; c=C(dataset_id='{id}'); c.connect(); print(c.list_tables())"

Tell the user: the analyst now queries this warehouse for every request, and each query is logged for provenance. For day-to-day "am I on live or local?" checks, use /connect-snowflake. Remind them that remote is opt-in: use_remote: true is set for this dataset, and AAP_USE_REMOTE=1 in the shell is the belt-and-suspenders guard.


Appendix (optional): the Snowflake MCP server

Only if the user specifically wants the interactive snowflake-labs-mcp query tool in addition to the native path. The analyst does not query through it, so this is not required for setup.

  1. Install uv: curl -LsSf https://astral.sh/uv/install.sh | sh, then ~/.local/bin/uvx --version.
  2. Create snowflake-mcp-config.yaml with read-only SQL permissions:
    yaml
    other_services: {object_manager: true, query_manager: true, semantic_manager: true}
    sql_statement_permissions:
      - Select: true
      - Create: false
      - Drop: false
      - Update: false
      - Delete: false
      - Insert: false
  3. Add a snowflake server to .mcp.json (preserve other servers). The command is the absolute path to uvx; credentials go in args as explicit flags (--account, --user, --warehouse, --password) because the server ignores the env block. Do NOT use --connection-name.
  4. Restart Claude Code so the MCP config loads, then query with the MCP run_snowflake_query tool: SELECT CURRENT_ACCOUNT(), CURRENT_WAREHOUSE(), CURRENT_VERSION().

© ai-analyst-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/setup-snowflake of ai-analyst-lab/ai-analyst.

Open the folder on GitHubat commit 52c0744

Compare with similar skills

Setup Snowflake next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setup Snowflake compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setup Snowflake this skillai-analyst-lab/ai-analyst304—~2kAutomated safety check: NotesMIT
Migrating To Amazon Redshiftaws/agent-toolkit-for-aws2.8k—~2.7kAutomated safety check: NotesApache-2.0
Setup Snowflakeopenshift-eng/ai-helpers120—~1.9kAutomated safety check: NotesApache-2.0
Agent BomLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.0
Clickhouse Best Practicesvemetric/vemetric3942 repos~2.6kAutomated safety check: PassApache-2.0
Webapp Buildersidequery/sidemantic129—~5.5kAutomated safety check: PassAGPL-3.0

Similar skills

  • Migrating To Amazon Redshift

    aws/agent-toolkit-for-aws

    Official

    Guides an end-to-end data-warehouse migration to Amazon Redshift — discovery, schema/SQL/stored-procedure/macro/script conversion, data migration, validation, performance comparison, and reporting.

    2.8k GitHub stars~2.7k tokensUpdated today
    DatabasesAuto-check: notes
  • Setup Snowflake

    openshift-eng/ai-helpers

    This skill should be used before any Snowflake command to verify MCP connectivity, guide users through access provisioning, and set the session context.

    120 GitHub stars~1.9k tokensUpdated today
    DatabasesAuto-check: notes
  • Agent Bom

    LeoYeAI/openclaw-master-skills

    Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Clickhouse Best Practices

    vemetric/vemetric

    MUST USE when reviewing ClickHouse schemas, queries, or configurations.

    394 GitHub starsUsed in 2 repos~2.6k tokens
    DatabasesAuto-check passed
  • Webapp Builder

    sidequery/sidemantic

    Build interactive analytics webapps, demos, dashboards, or embedded app surfaces from Sidemantic semantic models using copyable component primitives and deterministic query inspection.

    129 GitHub stars~5.5k tokensUpdated today
    DatabasesAuto-check passed
  • Ade Bench Cross DB Tasks

    dbt-labs/ade-bench

    Official

    A skill your agent uses when authoring or debugging ade-bench tasks that must run on both DuckDB and Snowflake, including shared project migrations, setup patches, and solution patches

    125 GitHub stars~2k tokensUpdated 7 days ago
    DatabasesAuto-check passed

More from ai-analyst-lab/ai-analyst

All 43 skills in this repo
  • Always Compare

    ai-analyst-lab/ai-analyst

    Never present a metric or number in isolation; anchor every number to a comparison (prior period, benchmark, or another segment) or state that none is available.

    304 GitHub stars~1.4k tokensUpdated 6 days ago
    Auto-check passed
  • Archaeology

    ai-analyst-lab/ai-analyst

    Retrieve proven SQL patterns, table cheatsheets, and join patterns from .knowledge/query-archaeology/ so past work gets reused.

    304 GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed
  • Archive Analysis

    ai-analyst-lab/ai-analyst

    Save completed analyses to the knowledge system's analysis archive for future reference.

    304 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check passed
  • Auth Preflight

    ai-analyst-lab/ai-analyst

    Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).

    304 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check passed
  • Causal

    ai-analyst-lab/ai-analyst

    Causal inference toolkit for when experiments are not possible: estimate treatment effects from observational data with assumption checks and mandatory caveats.

    304 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed
  • Chart To Drive

    ai-analyst-lab/ai-analyst

    Standardized workflow for uploading local chart PNGs to Google Drive and making them available for insertion into Google Docs and Slides.

    304 GitHub stars~1.4k tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Setup Snowflake

What does Setup Snowflake do?

First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance). Setup Snowflake is an agent skill from ai-analyst-lab/ai-analyst. First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance).

When should I use Setup Snowflake?

Setup Snowflake fits situations like: the user says set up snowflake; connect to snowflake; configure the warehouse; is routed here from /connect-data.

How do I install Setup Snowflake in Claude Code?

Run `npx skills add ai-analyst-lab/ai-analyst --skill setup-snowflake -a claude-code`. Or copy the skill folder (.claude/skills/setup-snowflake in ai-analyst-lab/ai-analyst) into .claude/skills/setup-snowflake in your project. Claude Code loads it when a task matches its description.

How do I install Setup Snowflake in Codex?

Run `npx skills add ai-analyst-lab/ai-analyst --skill setup-snowflake -a codex`. Or copy the skill folder (.claude/skills/setup-snowflake in ai-analyst-lab/ai-analyst) into .agents/skills/setup-snowflake in your project. Codex loads it when a task matches its description.

Can I use Setup Snowflake in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ai-analyst-lab/ai-analyst --skill setup-snowflake -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-snowflake, .gemini/skills/setup-snowflake, .github/skills/setup-snowflake and .opencode/skills/setup-snowflake in your project.

What does Setup Snowflake need to run?

Going by SKILL.md and its folder, Setup Snowflake needs the command-line tools its instructions call (python3, pip, bash, curl, sh and uvx) and credentials named SNOWFLAKE_PASSWORD and SNOWFLAKE_TOKEN. Our summary lists: Python 3; A credential in SNOWFLAKE_TOKEN.

Does Setup Snowflake access the network?

SKILL.md names 1 domain. In commands or code: astral.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Setup Snowflake safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Setup Snowflake use?

Setup Snowflake is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setup Snowflake use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Setup Snowflake?

Skills that share tags, products or a category with Setup Snowflake: Migrating To Amazon Redshift (aws/agent-toolkit-for-aws, 2.8k stars), Setup Snowflake (openshift-eng/ai-helpers, 120 stars), Agent Bom (LeoYeAI/openclaw-master-skills, 2.2k stars) and Clickhouse Best Practices (vemetric/vemetric, 394 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setup Snowflake?

ai-analyst-lab (a GitHub organization) maintains it in ai-analyst-lab/ai-analyst, which has 304 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on September 30, 2026.

Source: ai-analyst-lab/ai-analyst on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.