Agent skill

Snowflake Access Guardian

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit Snowflake effective access and produce a safe least-privilege change packet.

MITAuto-check passedDatabases

Install Snowflake Access Guardian

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-access-guardian -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace snowflake-access-guardian --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/snowflake-access-guardian .claude/skills/snowflake-access-guardian && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
snowflake-access-guardian
GitHub stars
2.8k
Token cost
~3.2k tokens
SKILL.md length
1,248 words
Files
23 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit Snowflake effective access and produce a safe least-privilege change packet.

  • Works in 7 steps: Establish the principal, target object,… → Collect the delayed account-wide… → Collect current evidence only for the… → …
  • Access is unexpectedly broad
  • SKILL.md covers Overview, Prerequisites, Authentication and Safety contract, plus 7 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Snowflake Access Guardian is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit Snowflake effective access and produce a safe least-privilege change packet. Trace account-role inheritance, primary and secondary roles, managed-access schemas, ownership, direct-to-user/PUBLIC grants, orphaned principals, and existing-versus-future-grant conflicts. Use when access is unexpectedly broad or denied, a role graph needs review, or an authorization cleanup needs evidence. Trigger with phrases like "Snowflake access audit", "trace Snowflake grants", "why can this user read", "Snowflake RBAC…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 25 other files, including scripts and reference files (for example `eval-spec.yaml`, `references/audit-queries.md` and `references/authorization-model.md`). Compatibility notes: Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection

It sits in Databases, covering Data warehousing and Authorization and RBAC. It works with Snowflake. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Access is unexpectedly broad
  • A role graph needs review
  • An authorization cleanup needs evidence
  • With phrases like Snowflake access audit

Example prompts

  • “Snowflake access audit”
  • “trace Snowflake grants”
  • “why can this user read”
  • “/snowflake-access-guardian”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection
  • Pre-approved tools (allowed-tools): Read, Write, Bash(python3:*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Establish the principal, target object, privilege, evidence timestamp, review
  2. Collect the delayed account-wide baseline with a role holding Snowflake's
  3. Collect current evidence only for the declared review scope. Capture the
  4. At the controlled local collection boundary, assemble the bundle and record its
  5. For each finding, distinguish observed, not proven, and **needs live
  6. Produce a dry-run change packet: current path, intended path, exact proposed
  7. Require positive and negative verification before an authorized operator

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash(python3:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 11 files in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection

    From compatibility in the SKILL.md frontmatter.

Context cost

Snowflake Access Guardian loads about 3.2k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,248 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,248 words, ~3,190 tokens.

Download SKILL.mdSave it as .claude/skills/snowflake-access-guardian/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.
name
snowflake-access-guardian
description
Audit Snowflake effective access and produce a safe least-privilege change packet. Trace account-role inheritance, primary and secondary roles, managed-access schemas, ownership, direct-to-user/PUBLIC grants, orphaned principals, and existing-versus-future-grant conflicts. Use when access is unexpectedly broad or denied, a role graph needs review, or an authorization cleanup needs evidence. Trigger with phrases like "Snowflake access audit", "trace Snowflake grants", "why can this user read", "Snowflake RBAC drift", or "future grants conflict".
allowed-tools
Read, Write, Bash(python3:*)
compatibility
Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection
argument-hint
[redacted-access-evidence.json]
version
3.16.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, snowflake, security, rbac, governance, least-privilege

Snowflake Access Guardian

Overview

Turn a sanitized Snowflake authorization inventory into an evidence-backed effective-access trace and a dry-run remediation packet. This is the focused Snowflake counterpart to a generic RBAC explainer: it catches the failure modes that make enterprise reviews expensive—role inheritance that was not followed, direct user and PUBLIC grants, abandoned grantees, ownership control, managed access semantics, secondary-role assumptions, and future-grant precedence.

Prerequisites

  • Receipted, sanitized outputs from the bundled historical, session, role, user, database-role, and relevant database/schema future-grant collectors.
  • A named principal/object/privilege question, account/role identity, UTC collection timestamp, observation window, and explicit freshness bound. Live Snowflake checks remain the operator's responsibility.
  • Timestamped positive (allowed action) and negative (denied action) receipts captured under the same primary/secondary-role context; missing proof is NOT_PROVEN, never an inferred denial.
  • Python 3.10+ for the bundled stdlib analyzer. No Snowflake driver or network access is required.

Authentication

This skill's analyzer is offline and deliberately has no authentication flow. If live Snowflake evidence is collected, use the organization's approved Snowflake session/authentication process; never put its credentials in the inventory or report. Use Write only to save a sanitized report or approved local change packet; never to apply Snowflake mutations.

Safety contract

  • Read-only by default. The analyzer does not connect to Snowflake and never executes GRANT, REVOKE, GRANT OWNERSHIP, ALTER USER, or policy changes.
  • Accept sanitized metadata only. Do not provide passwords, tokens, private keys, raw connection strings, or access-history payloads containing sensitive data.
  • Do not infer denial from a missing historical row. Account Usage can lag by up to 120 minutes and has documented object/shared-role omissions.
  • Never broaden to ACCOUNTADMIN or automatically grant MANAGE GRANTS to get a more complete snapshot. MANAGE GRANTS can administer grants and is not a read-only privilege, even when this collector executes only SHOW statements.
  • Do not infer that a role is unused from one telemetry source. Name the review period, object coverage, and evidence gaps.
  • Treat ownership as control-plane authority and future OWNERSHIP as a separate high-risk decision. Never auto-generate executable mutation SQL.

Workflow

  1. Establish the principal, target object, privilege, evidence timestamp, review period, and whether the question is about a primary-role or secondary-role session. Read authorization-model.md for path and evidence rules.

  2. Collect the delayed account-wide baseline with a role holding Snowflake's SNOWFLAKE.SECURITY_VIEWER database role. Preserve the receipt unchanged:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access --connection <existing-readonly-profile> \
      --output ./snowflake-access-historical.json
  3. Collect current evidence only for the declared review scope. Capture the session context without changing roles, then collect grants to and grants of each account role, target-user roles, involved database roles, and paired database/schema future grants:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access-session --connection <profile> --output ./session.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access-role-current --role DATA_READER \
      --connection <profile> --output ./role-current.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access-role-parents --role DATA_READER \
      --connection <profile> --output ./role-parents.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access-future-database --database ANALYTICS \
      --connection <profile> --output ./future-database.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface access-future-schema --schema ANALYTICS.CURATED \
      --connection <profile> --output ./future-schema.json

    Selectors accept only supported one-part or two-part unquoted identifiers; quoted/multipart identifiers need a separately reviewed collection path. Each scoped SHOW uses one Snowflake pipe statement that emits both the allowlisted rows and its execution context. Invocations may use different physical sessions; the analyzer requires equivalent account, user, primary role, role type, and secondary-role state. Saved/offline access JSON is not accepted as current evidence. Read current-evidence-contract.md for every surface and the schema 2.0 bundle. Permission errors, missing declared selectors, a missing current PUBLIC role receipt, cap hits, or an unpaired schema receipt remain blockers.

  4. At the controlled local collection boundary, assemble the bundle and record its canonical digest separately. Analyze the exact same bundle with that digest:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_access_evidence.py" \
      --input ./snowflake-access-bundle.json --print-input-sha256
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_access_evidence.py" \
      --input ./snowflake-access-bundle.json \
      --trusted-input-sha256 sha256:<separately-recorded-digest> \
      --out ./snowflake-access-report.json

    The receipt analyzer validates templates, selectors, sources, row counts, caps, Snowflake observation timestamps, request-derived coverage, equivalent authorization contexts, and the bundle digest before invoking the graph analyzer. The matching digest is an operator assertion of byte identity, not authentication; computing it from an untrusted copy creates no trust. analyze_access.py remains a diagnostic path for legacy sanitized inventories, but it cannot establish receipted completeness.

  5. For each finding, distinguish observed, not proven, and needs live verification. Resolve managed-access, ownership, and future-grant findings with managed-access-and-future-grants.md. The report must retain direct-user paths and every ownership path separately; ownership is control-plane authority, not routine access.

  6. Produce a dry-run change packet: current path, intended path, exact proposed principal/privilege/object edge, approver, executor, precondition, reversal, and residual risk. Proposed SQL may be described as a review artifact, but it is not executed by this skill.

  7. Require positive and negative verification before an authorized operator applies anything. Use verification-and-rollback.md for receipt fields and rollback boundary. When database- and schema-level future grants overlap, report effective schema precedence and test a disposable object; do not summarize the conflict as a generic duplicate.

Show full SKILL.md (530 more words)Show less

What the report must answer

  • Which paths prove the requested access, including inherited and secondary-role context? If no path is in the sanitized inventory, say NOT_PROVEN, not denied.
  • Is access direct to a user, through PUBLIC, through an orphaned grantee, or through a role chain that should be reviewed?
  • If access is direct to a user, was user-based access actually active through USE SECONDARY ROLES ALL? NONE or an explicit role list does not activate it.
  • Is the object owned by a role whose control is broader than routine access?
  • Is the schema managed access, and is the grantor evidence sufficient?
  • Does any schema-level future grant suppress database-level definitions for the same object type in that schema—even for different grantees or privileges—or does a future OWNERSHIP grant need explicit approval?
  • Which live checks remain necessary: container USAGE, policies, shares, SHOW GRANTS, current secondary-role mode, and a real allowed/denied operation?
  • Is the evidence fresh for this decision, and do timestamped positive and negative access proofs exist for the requested role/object context?

Output

Return a JSON report plus a human-readable change packet containing:

  • deterministic input SHA-256 and inventory scope;
  • object-privilege paths and OBJECT_PRIVILEGE_PATH_PROVEN/NOT_PROVEN status; this never certifies complete access without separate container/policy checks;
  • separate object_privilege_path_supported and positive_access_claim_supported booleans; the latter also requires a matching positive behavior receipt;
  • sorted findings with severity, evidence, and remediation decision;
  • managed-access and secondary-role boundaries;
  • evidence scope/freshness, direct-user and ownership paths, and explicit database-versus-schema future-grant precedence;
  • per-receipt contract status, trusted-bundle status, declared-selector coverage, and current-versus-historical drift classifications;
  • proposed change/reversal descriptions with no executed mutations; and
  • positive and negative verification receipts with PROVEN/NOT_PROVEN status.

Error Handling

ConditionResponse
Credential-bearing field appearsStop; remove it and rerun with metadata only.
Role or user is absent from inventoryMark path NOT_PROVEN; do not create or delete a principal.
Account Usage disagrees with SHOW GRANTSTreat live/current evidence as a separate reconciliation; record lag and scope.
Current SHOW visibility is incompleteRecord the collector role and block absence claims; never grant MANAGE GRANTS automatically.
Receipt lacks a separate matching bundle digestReport UNTRUSTED, suppress graph claims, and block completeness.
Any receipt lacks same-statement context or a fresh server observationSuppress graph claims and recollect live.
Database future receipt lacks the target schema receiptBlock precedence and completeness claims.
Managed schema lacks grantor/owner evidenceStop remediation proposal until MANAGE GRANTS and ownership are verified.
Future grants overlapReconcile schema precedence and test a disposable object before approval.
Ownership or PUBLIC access is involvedRequire named security/data owner approval and an independent rollback path.

Examples

Trace one path

Put ALICE, ANALYTICS.CURATED.ORDERS, and SELECT in the schema 2.0 bundle's request, then run analyze_access_evidence.py. A result such as ALICE -> ANALYST -> DATA_READER is a positively supported path; a missing path never unblocks an absence or denial claim.

Review a cleanup request

For “revoke everything suspicious,” report direct-user/PUBLIC/orphan findings, future-grant precedence, and the required positive/negative tests. Keep changes as a dry-run packet for the authorized operator.

References

The four linked references contain the maintained decision detail and official Snowflake primary sources; load only those relevant to the current finding.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 22 other files (scripts, references) in skills/.curated/snowflake-access-guardian of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • references/audit-queries.md
  • references/authorization-model.md
  • references/current-evidence-contract.md
  • references/managed-access-and-future-grants.md
  • references/verification-and-rollback.md
  • scripts/analyze_access.py
  • scripts/analyze_access_evidence.py
  • scripts/collect_snowflake_evidence.py
  • scripts/sql/access-database-role-current.sql
  • scripts/sql/access-future-database.sql
  • scripts/sql/access-future-schema.sql
  • scripts/sql/access-role-current.sql
  • scripts/sql/access-role-parents.sql
  • scripts/sql/access-session.sql
  • scripts/sql/access-user-current.sql
  • scripts/sql/access.sql
  • … and 5 more

Open the folder on GitHubat commit cfae287

Compare with similar skills

Snowflake Access Guardian next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Snowflake Access Guardian compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Snowflake Access Guardian this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.2kAutomated safety check: PassMIT
Snowflake Data EngineeringMindrally/skills271—~2.3kAutomated safety check: PassApache-2.0
Caspian DiscordTryCaspian/caspian-sdk973—~323Automated safety check: PassApache-2.0
Write Script Snowflakewindmill-labs/windmill18k—~2.2kAutomated safety check: PassCustom licence
Pure Lsp Execute Parallelfinos/legend-engine113—~927Automated safety check: PassApache-2.0
Snowflakeadobe/skills197—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Best practices for Snowflake SQL, semi-structured data, and data pipelines built with Dynamic Tables, Streams, Tasks, and Snowpipe.

    271 GitHub stars~2.3k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Caspian Discord

    TryCaspian/caspian-sdk

    Post a Discord message via Caspian to a channel snowflake id.

    973 GitHub stars~323 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Write Script Snowflake

    windmill-labs/windmill

    MUST use when writing Snowflake queries. An agent skill from windmill-labs/windmill.

    18k GitHub stars~2.2k tokensUpdated today
    DatabasesAuto-check passed
  • Pure Lsp Execute Parallel

    finos/legend-engine

    Runs 2 to 30 Pure functions or tests concurrently on the warm LSP daemon via pure-lsp execute-parallel, or every test in a package or .pure file with --package/--source.

    113 GitHub stars~927 tokensUpdated yesterday
    DatabasesAuto-check passed
  • Snowflake

    adobe/skills

    Use this when converting an AI-generated static HTML page (Stardust, Mobirise, Relume, Lovable, v0, Figma-derived, etc.) into an Edge Delivery Services page while preserving the original design and…

    197 GitHub stars~3.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Sap Datasphere

    secondsky/sap-skills

    SAP Datasphere development skill with 3 specialized agents, 5 slash commands, and validation hooks.

    462 GitHub stars~6k tokensUpdated 6 days ago
    DatabasesAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Snowflake Access Guardian

What does Snowflake Access Guardian do?

Audit Snowflake effective access and produce a safe least-privilege change packet. Snowflake Access Guardian is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit Snowflake effective access and produce a safe least-privilege change packet.

When should I use Snowflake Access Guardian?

Snowflake Access Guardian fits situations like: access is unexpectedly broad; A role graph needs review; an authorization cleanup needs evidence; with phrases like Snowflake access audit.

How do I install Snowflake Access Guardian in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-access-guardian -a claude-code`. Or copy the skill folder (skills/.curated/snowflake-access-guardian in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/snowflake-access-guardian in your project. Claude Code loads it when a task matches its description.

How do I install Snowflake Access Guardian in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-access-guardian -a codex`. Or copy the skill folder (skills/.curated/snowflake-access-guardian in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/snowflake-access-guardian in your project. Codex loads it when a task matches its description.

Can I use Snowflake Access Guardian in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-access-guardian -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/snowflake-access-guardian, .gemini/skills/snowflake-access-guardian, .github/skills/snowflake-access-guardian and .opencode/skills/snowflake-access-guardian in your project.

What does Snowflake Access Guardian need to run?

Going by SKILL.md and its folder, Snowflake Access Guardian needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*). Compatibility (from SKILL.md): Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection.

Does Snowflake Access Guardian access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Snowflake Access Guardian safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Snowflake Access Guardian use?

Snowflake Access Guardian is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Snowflake Access Guardian use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.

What are the alternatives to Snowflake Access Guardian?

Skills that share tags, products or a category with Snowflake Access Guardian: Snowflake Data Engineering (Mindrally/skills, 271 stars), Caspian Discord (TryCaspian/caspian-sdk, 973 stars), Write Script Snowflake (windmill-labs/windmill, 18k stars) and Pure Lsp Execute Parallel (finos/legend-engine, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Snowflake Access Guardian?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.