Agent skill

Snowflake Governance Coverage Auditor

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data.

MITAuto-check passedDatabases

Install Snowflake Governance Coverage Auditor

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-governance-coverage-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace snowflake-governance-coverage-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/snowflake-governance-coverage-auditor .claude/skills/snowflake-governance-coverage-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
snowflake-governance-coverage-auditor
GitHub stars
2.8k
Token cost
~1.8k tokens
SKILL.md length
581 words
Files
14 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data.

  • Works in 5 steps: Have the governance owner approve the… → Collect one classification receipt per… → Independently verify the collection… → …
  • Governance enforcement may be missing
  • SKILL.md covers Purpose, Prerequisites, Workflow and Decision boundaries, plus 4 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Snowflake Governance Coverage Auditor is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data. Use when governance enforcement may be missing or ambiguous. Trigger with "Snowflake governance coverage", "policy precedence", "tag policy gaps", "classification failure", or "POLICYCONTEXT verification".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `eval-spec.yaml`, `references/current-state.md` and `references/input-contract.md`). Compatibility notes: Model-neutral; requires Python 3.10+. Optional collection requires Snowflake CLI and an existing least-privilege profile.

It sits in Databases, covering Data warehousing and Privacy and GDPR. It works with Snowflake. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Governance enforcement may be missing
  • With Snowflake governance coverage
  • Policy precedence
  • Tag policy gaps

Example prompts

  • “Snowflake governance coverage”
  • “policy precedence”
  • “tag policy gaps”
  • “/snowflake-governance-coverage-auditor”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Model-neutral; requires Python 3.10+. Optional collection requires Snowflake CLI and an existing least-privilege profile.
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*)

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Have the governance owner approve the exact asset and simulation denominator.
  2. Collect one classification receipt per database and one tag plus one policy
  3. Independently verify the collection role's complete visibility over exactly
  4. Record evidence and policy digests at their independent trusted boundaries
  5. Analyze only with the previously recorded digests and policy-bound clock

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.snowflake.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Model-neutral; requires Python 3.10+. Optional collection requires Snowflake CLI and an existing least-privilege profile.

    From compatibility in the SKILL.md frontmatter.

Context cost

Snowflake Governance Coverage Auditor loads about 1.8k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 581 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 581 words, ~1,776 tokens.

Download SKILL.mdSave it as .claude/skills/snowflake-governance-coverage-auditor/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
snowflake-governance-coverage-auditor
description
Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data. Use when governance enforcement may be missing or ambiguous. Trigger with "Snowflake governance coverage", "policy precedence", "tag policy gaps", "classification failure", or "POLICY_CONTEXT verification".
allowed-tools
Read, Bash(python3:*)
compatibility
Model-neutral; requires Python 3.10+. Optional collection requires Snowflake CLI and an existing least-privilege profile.
argument-hint
[schema-2-evidence.json]
model
inherit
effort
high
version
3.16.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
saas, snowflake, governance, classification, masking, row-access, privacy

Snowflake Governance Coverage Auditor

Purpose

Compare an owner-approved hashed denominator with trusted schema-2 current receipts and separately trusted, sanitized POLICY_CONTEXT simulations. Missing, stale, capped, privilege-filtered, unsupported, or context-mismatched evidence is never a pass; the result distinguishes observable coverage from evidence gaps without exposing governed data or claiming compliance.

Read the input contract and the source notes before assembling evidence.

Prerequisites

Use Python 3.10+, an owner-approved hashed denominator, and an existing Snowflake CLI read-only profile. Establish independent evidence and policy trust boundaries before analysis; do not accept credentials, raw identifiers, policy text, tag values, customer rows, or ad hoc SQL.

Workflow

  1. Have the governance owner approve the exact asset and simulation denominator.

  2. Collect one classification receipt per database and one tag plus one policy receipt per governed object. Use fixed unquoted selectors only:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface governance-classification-current --connection readonly-observer \
      --governance-database GOVERNED_DB --output ./classification.json
    
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface governance-tags-current --connection readonly-observer \
      --governance-object GOVERNED_DB.GOVERNED_SCHEMA.GOVERNED_TABLE \
      --governance-domain TABLE --output ./tags.json
    
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface governance-policies-current --connection readonly-observer \
      --governance-object GOVERNED_DB.GOVERNED_SCHEMA.GOVERNED_TABLE \
      --governance-domain TABLE --output ./policies.json
  3. Independently verify the collection role's complete visibility over exactly those hashes and produce the scope receipt. Execute the approved POLICY_CONTEXT cases outside this collector; retain only the strict hash-only receipt contract. Never add EXECUTE USING to the shared collector.

  4. Record evidence and policy digests at their independent trusted boundaries:

    bash
    # Record only at trusted local boundaries.
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_governance.py" evidence.json \
      --print-input-sha256
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_governance.py" evidence.json \
      --policy-file policy.json --print-policy-sha256
  5. Analyze only with the previously recorded digests and policy-bound clock:

    bash
    # Replace the quoted placeholder with the owner-policy timestamp.
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_governance.py" evidence.json \
      --policy-file policy.json --evaluated-at "YYYY-MM-DDTHH:MM:SSZ" \
      --trusted-input-sha256 sha256:RECORDED_EVIDENCE_DIGEST \
      --trusted-policy-sha256 sha256:RECORDED_POLICY_DIGEST --pretty

Recomputing a digest from suspect evidence is not trust. Preserve every finding, precedence observation, non-claim, and the dry-run remediation packet.

Decision boundaries

  • Unknown or Standard edition, unverified preview support, missing scope proof, role filtering, caps, duplicates, mixed contexts, or stale receipts suppress a positive bounded result.
  • Account Usage classification is latency-bounded observation. A newer failed attempt, absent profile-scope proof, non-current status, or stale success is a gap. CREATE OR REPLACE profile operations can detach automatic classification and must be reviewed separately.
  • Direct policy assignments take precedence over tag assignments. For aggregation policies, a direct assignment shadows a tag assignment only for the same entity keys; different entity-key sets remain cumulative.
  • Any relevant non-ACTIVE provider status, including a missing conditional masking secondary argument, is a gap.
  • Row access evaluates before masking. Projection applies to final output only; it is not proof against inner-query or WHERE exposure.
  • Tag-based masking is generally available. Tag-based row access, projection, join, and aggregation require explicit owner-attested preview support.
  • Privacy-policy combinations with masking, aggregation, or projection remain a blocked design review even when assignment succeeds.
  • Every owner-approved sanitized simulation for each asset/control pair is cumulative; any mismatch or error blocks coverage. Each role, context, query-shape, expected outcome, account, and trusted input digest must match.
Show full SKILL.md (178 more words)Show less

Output

The collector uses reviewed SELECT statements only; it does not execute POLICY_CONTEXT, mutation SQL, shell payloads, or network operations. Receipts and reports contain only organization/account-scoped hashes, fixed enums, timestamps, counts, and booleans. Never collect policy bodies, tag values, names, customer rows, SQL text, errors, secrets, or query results. Exit 2 is a fixed generic invalid-evidence error and never reflects rejected input.

Every remediation item has mutation_sql: null and requires_separate_authorization: true. The skill never applies tags, policies, profiles, grants, feature flags, or edition changes.

Error Handling

Exit 2 means the evidence, policy, trust digest, freshness, context, cap, or schema check failed. The fixed error intentionally omits rejected values. Recheck the independent denominator and recollect; never infer health or escalate roles.

Example

An inherited required tag plus one ACTIVE applicable policy and a matching simulation can support bounded coverage. A missing secondary masking argument, newer failed classification attempt, unverified preview, or missing scope receipt produces a fixed hash-scoped gap and a non-executable remediation item.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/.curated/snowflake-governance-coverage-auditor of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • references/current-state.md
  • references/input-contract.md
  • references/privilege-and-boundaries.md
  • references/source-notes.md
  • scripts/analyze_governance.py
  • scripts/collect_snowflake_evidence.py
  • scripts/sql/governance-classification-current.sql
  • scripts/sql/governance-policies-current.sql
  • scripts/sql/governance-tags-current.sql
  • tests/fixtures/clean-observations.json
  • tests/fixtures/unsafe-observations.json
  • tests/test_analyze_governance.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Snowflake Governance Coverage Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Snowflake Governance Coverage Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Snowflake Governance Coverage Auditor this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT
Caspian DiscordTryCaspian/caspian-sdk973—~323Automated safety check: PassApache-2.0
Write Script Snowflakewindmill-labs/windmill18k—~2.2kAutomated safety check: PassCustom licence
Pure Lsp Execute Parallelfinos/legend-engine113—~927Automated safety check: PassApache-2.0
Snowflakeadobe/skills197—~3.7kAutomated safety check: PassApache-2.0
Schema Design InterviewerPrepLabsAI/InterviewMentor112—~8.2kAutomated safety check: PassMIT

Similar skills

  • Caspian Discord

    TryCaspian/caspian-sdk

    Post a Discord message via Caspian to a channel snowflake id.

    973 GitHub stars~323 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Write Script Snowflake

    windmill-labs/windmill

    MUST use when writing Snowflake queries. An agent skill from windmill-labs/windmill.

    18k GitHub stars~2.2k tokensUpdated today
    DatabasesAuto-check passed
  • Pure Lsp Execute Parallel

    finos/legend-engine

    Runs 2 to 30 Pure functions or tests concurrently on the warm LSP daemon via pure-lsp execute-parallel, or every test in a package or .pure file with --package/--source.

    113 GitHub stars~927 tokensUpdated yesterday
    DatabasesAuto-check passed
  • Snowflake

    adobe/skills

    Use this when converting an AI-generated static HTML page (Stardust, Mobirise, Relume, Lovable, v0, Figma-derived, etc.) into an Edge Delivery Services page while preserving the original design and…

    197 GitHub stars~3.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Schema Design Interviewer

    PrepLabsAI/InterviewMentor

    A Data Warehouse and Lakehouse Schema Design Expert interviewer focused on dimensional modeling, star/snowflake schemas, analytics optimization, and modern lakehouse architectures.

    112 GitHub stars~8.2k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Neo4j Aura Graph Analytics Skill

    neo4j-contrib/neo4j-skills

    Serverless Aura Graph Analytics (AGA) GDS Sessions — covers GdsSessions, AuraGraphDataScience, AuraAPICredentials, DbmsConnectionInfo, SessionMemory, getorcreate, remote graph projection with…

    114 GitHub stars~4.6k tokensUpdated yesterday
    DatabasesAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Snowflake Governance Coverage Auditor

What does Snowflake Governance Coverage Auditor do?

Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data. Snowflake Governance Coverage Auditor is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data.

When should I use Snowflake Governance Coverage Auditor?

Snowflake Governance Coverage Auditor fits situations like: governance enforcement may be missing; with Snowflake governance coverage; policy precedence; tag policy gaps.

How do I install Snowflake Governance Coverage Auditor in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-governance-coverage-auditor -a claude-code`. Or copy the skill folder (skills/.curated/snowflake-governance-coverage-auditor in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/snowflake-governance-coverage-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Snowflake Governance Coverage Auditor in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-governance-coverage-auditor -a codex`. Or copy the skill folder (skills/.curated/snowflake-governance-coverage-auditor in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/snowflake-governance-coverage-auditor in your project. Codex loads it when a task matches its description.

Can I use Snowflake Governance Coverage Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-governance-coverage-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/snowflake-governance-coverage-auditor, .gemini/skills/snowflake-governance-coverage-auditor, .github/skills/snowflake-governance-coverage-auditor and .opencode/skills/snowflake-governance-coverage-auditor in your project.

What does Snowflake Governance Coverage Auditor need to run?

Going by SKILL.md and its folder, Snowflake Governance Coverage Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*). Compatibility (from SKILL.md): Model-neutral; requires Python 3.10+. Optional collection requires Snowflake CLI and an existing least-privilege profile..

Does Snowflake Governance Coverage Auditor access the network?

SKILL.md names 1 domain. As links in the text: docs.snowflake.com. This is read from the text; nothing was executed.

Is Snowflake Governance Coverage Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Snowflake Governance Coverage Auditor use?

Snowflake Governance Coverage Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Snowflake Governance Coverage Auditor use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Snowflake Governance Coverage Auditor?

Skills that share tags, products or a category with Snowflake Governance Coverage Auditor: Caspian Discord (TryCaspian/caspian-sdk, 973 stars), Write Script Snowflake (windmill-labs/windmill, 18k stars), Pure Lsp Execute Parallel (finos/legend-engine, 113 stars) and Snowflake (adobe/skills, 197 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Snowflake Governance Coverage Auditor?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.