Agent skill

Snowflake Native App Release Sheriff

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything.

MITAuto-check passedDatabases

Install Snowflake Native App Release Sheriff

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-native-app-release-sheriff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace snowflake-native-app-release-sheriff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/snowflake-native-app-release-sheriff .claude/skills/snowflake-native-app-release-sheriff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
snowflake-native-app-release-sheriff
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
767 words
Files
15 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything.

  • Works in 4 steps: Collect all three live provider surfaces… → Build the schema-2 packet with… → Run the analyzer at an explicit UTC… → …
  • Reviewing manifest/setup safety
  • SKILL.md covers Purpose, Prerequisites, Instructions and Fail-closed rules, plus 5 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Snowflake Native App Release Sheriff is an agent skill from jeremylongshore/tons-of-skills-marketplace. Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything. Use when reviewing manifest/setup safety, security-scan gates, version and release-directive validation, App Spec or privilege changes, upgrade-cohort compatibility, and rollback readiness. Trigger with "Native App release", "application package scan", "upgrade cohort", or "App Spec".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `eval-spec.yaml`, `fixtures/incompatible-versions.json` and `fixtures/missing-scans.json`). Compatibility notes: Model-agnostic; Python 3.10+; optional Snowflake CLI for live provider-side read-only collection

It sits in Databases, covering Data warehousing and Security review. It works with Snowflake. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing manifest/setup safety
  • Security-scan gates
  • Version and release-directive validation
  • Privilege changes

Example prompts

  • “Native App release”
  • “application package scan”
  • “upgrade cohort”
  • “/snowflake-native-app-release-sheriff”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Model-agnostic; Python 3.10+; optional Snowflake CLI for live provider-side read-only collection
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Collect all three live provider surfaces for one exact package.
  2. Build the schema-2 packet with owner-approved denominators and trusted hashes.
  3. Run the analyzer at an explicit UTC evaluation time.
  4. Stop on invalid, blocked, stale, capped, or incomplete evidence; hand a clean

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Model-agnostic; Python 3.10+; optional Snowflake CLI for live provider-side read-only collection

    From compatibility in the SKILL.md frontmatter.

Context cost

Snowflake Native App Release Sheriff loads about 2k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 767 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 767 words, ~2,033 tokens.

Download SKILL.mdSave it as .claude/skills/snowflake-native-app-release-sheriff/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
snowflake-native-app-release-sheriff
description
Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything. Use when reviewing manifest/setup safety, security-scan gates, version and release-directive validation, App Spec or privilege changes, upgrade-cohort compatibility, and rollback readiness. Trigger with "Native App release", "application package scan", "upgrade cohort", or "App Spec".
allowed-tools
Read, Bash(python3:*)
compatibility
Model-agnostic; Python 3.10+; optional Snowflake CLI for live provider-side read-only collection
argument-hint
[schema-2-native-app-evidence.json]
version
3.16.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
model
inherit
effort
high
tags
saas, snowflake, native-app, release, security, upgrade, rollback

Snowflake Native App Release Sheriff

Purpose

Produce a deterministic, as-of provider-side release preflight. A clean result is READY_FOR_OPERATOR_RELEASE_AS_OF, never permission or an instruction to publish, set a release directive, upgrade an application, or alter privileges.

Prerequisites

Read both reference files before analysis. The input must use the exact schema-2 contract in references/evidence-contract.md and must include independently retained hashes for the whole bundle, manifest, setup script, normalized cohort rows/denominators, lifecycle evidence, and the complete rollback receipt including its artifact digest. Every array carries an explicit count; zero is evidence only when the owner-approved denominator is exactly zero.

Python 3.10+ is required. A Snowflake CLI profile is optional for collection and must already exist; authentication is configured outside this skill. The package manifest and setup script remain local inputs. Never send source SQL, package names, consumer names, account names, free-text scan failures, or App Spec definitions through the evidence packet. Use stable, account-scoped hashes.

Instructions

  1. Collect all three live provider surfaces for one exact package.
  2. Build the schema-2 packet with owner-approved denominators and trusted hashes.
  3. Run the analyzer at an explicit UTC evaluation time.
  4. Stop on invalid, blocked, stale, capped, or incomplete evidence; hand a clean as-of report to the separately authorized release owner.
Collect current provider evidence

Use an existing least-privilege Snowflake CLI profile with visibility to the selected package. The collector uppercases and strictly validates the unquoted one-part package selector, then binds the rendered-query receipt to the Snowflake-produced selected-package hash. An error receipt contains no package fingerprint.

bash
python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
  --surface native-app-versions-current --application-package APP_PACKAGE \
  --connection native-app-observer --output ./versions.json

python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
  --surface native-app-release-directives-current --application-package APP_PACKAGE \
  --connection native-app-observer --output ./directives.json

python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
  --surface native-app-upgrade-cohorts-current --application-package APP_PACKAGE \
  --connection native-app-observer --output ./cohorts.json

SHOW VERSIONS requires package visibility. SHOW RELEASE DIRECTIVES requires package ownership or the documented package release/version management privilege. SNOWFLAKE.DATA_SHARING_USAGE.APPLICATION_STATE is provider-only, can lag up to 10 minutes, and does not retain uninstalled instances. Do not escalate to ACCOUNTADMIN; missing or filtered evidence blocks the preflight.

Analyze

Record the five hashes at independent trusted boundaries, then run:

bash
python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_native_app_release.py" \
  --input ./native-app-evidence.json --evaluated-at "$EVALUATED_AT_UTC" \
  --trusted-input-sha256 sha256:... \
  --trusted-manifest-sha256 sha256:... \
  --trusted-setup-sha256 sha256:... \
  --trusted-cohort-sha256 sha256:... \
  --trusted-lifecycle-sha256 sha256:... \
  --trusted-rollback-sha256 sha256:... \
  > ./native-app-preflight.json

Exit 0 means the bounded preflight passed. Exit 1 means valid but blocked; exit 2 means invalid/untrusted evidence. The analyzer writes stdout only.

Validate the packet

Confirm all three receipt ages, exact package/account hashes, source counts, independent digests, target scan row, observed cohort denominator, compatibility edges, lifecycle receipt, and rollback evidence before accepting exit 0.

Show full SKILL.md (405 more words)Show less

Fail-closed rules

  • Require a unique READY target version/patch. For an EXTERNAL ALPHA or DEFAULT release require APPROVED; QA does not initiate a security scan, so scan status is reported but is not invented as approval.
  • Setup runs on install and upgrade and can resume after failure. Reject forbidden context/import patterns, non-replay-safe statements, and any grant-destructive replacement not immediately restored at the next statement.
  • Manifest v2 is required for App Specs. PENDING, DECLINED, absent, stale, or sequence-invalid consumer approval evidence blocks. Provider package metadata does not prove consumer approval.
  • Bind every automated privilege, reference callback/object/privilege contract, and App Spec delta to an exact denominator. Removed privileges block. For manifest v2 automated grants, changing manifest_version is major-upgrade-only and changing the requested privilege list is not a patch operation.
  • Require compatibility proof for every observed current-version cohort. Block install/upgrade failures, queued work, retries/delay, in-flight states, target mismatch, or previous-version FINALIZING.
  • Require current lifecycle history alongside APPLICATION_STATE; the snapshot alone cannot prove completeness or explain an uninstalled instance.
  • Require a tested, hash-bound rollback artifact and observables for privilege and App Spec reconciliation. A release directive starts upgrades; it is not a validation result.
  • Reject stale (>15 minutes), capped, tampered, mixed-account, offline, or selector-unbound receipts. Do not convert absence into PASS.

Safety boundary

Never execute ALTER APPLICATION PACKAGE, add/drop version or patch, set/unset a release directive, publish a listing, approve an App Spec, run setup, upgrade an application, or grant/revoke a privilege. Produce a review packet for a separate, authorized human change window.

Output

The report contains only finite finding codes, exact denominators, an as-of status, explicit safe_to_publish: false and safe_to_upgrade: false, non-claims, and a deterministic report hash. It never repeats input rows or raw identifiers.

Error Handling

INVALID_EVIDENCE means the strict packet, receipt, type, hash, scope, cap, or freshness contract failed; it intentionally does not echo the rejected value. BLOCKED is well-formed evidence with one or more finite remediation codes. Recollect permission-filtered, stale, or capped surfaces with the same approved scope. Never fix missing evidence by escalating privileges or executing a change.

Examples

  • IN_PROGRESS on an EXTERNAL DEFAULT target yields SECURITY_SCAN_NOT_APPROVED.
  • A missing compatibility edge for one observed cohort yields INCOMPATIBLE_OR_UNTESTED_COHORT, even when every other instance is complete.
  • Fresh, trusted, uncapped evidence with replay-safe setup, approved scan, exact cohorts, lifecycle proof, and tested rollback yields only READY_FOR_OPERATOR_RELEASE_AS_OF with both mutation flags false.

References

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (scripts, references) in skills/.curated/snowflake-native-app-release-sheriff of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • fixtures/incompatible-versions.json
  • fixtures/missing-scans.json
  • fixtures/partial-setup-failure.json
  • fixtures/removed-grants.json
  • fixtures/safe-cohorts.json
  • references/evidence-contract.md
  • references/source-notes.md
  • scripts/analyze_native_app_release.py
  • scripts/collect_snowflake_evidence.py
  • scripts/sql/native-app-release-directives-current.sql
  • scripts/sql/native-app-upgrade-cohorts-current.sql
  • scripts/sql/native-app-versions-current.sql
  • scripts/test_analyze_native_app_release.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Snowflake Native App Release Sheriff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Snowflake Native App Release Sheriff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Snowflake Native App Release Sheriff this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Snowflake Developmentsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: PassMIT
Caspian DiscordTryCaspian/caspian-sdk973—~323Automated safety check: PassApache-2.0
Write Script Snowflakewindmill-labs/windmill18k—~2.2kAutomated safety check: PassCustom licence
Pure Lsp Execute Parallelfinos/legend-engine113—~927Automated safety check: PassApache-2.0
Snowflakeadobe/skills197—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Snowflake Development

    sickn33/agentic-awesome-skills

    Comprehensive Snowflake development assistant covering SQL best practices, data pipeline design (Dynamic Tables, Streams, Tasks, Snowpipe), Cortex AI functions, Cortex Agents, Snowpark Python, dbt…

    47k GitHub starsUsed in 2 repos~2.1k tokens
    DatabasesAuto-check passed
  • Caspian Discord

    TryCaspian/caspian-sdk

    Post a Discord message via Caspian to a channel snowflake id.

    973 GitHub stars~323 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Write Script Snowflake

    windmill-labs/windmill

    MUST use when writing Snowflake queries. An agent skill from windmill-labs/windmill.

    18k GitHub stars~2.2k tokensUpdated today
    DatabasesAuto-check passed
  • Pure Lsp Execute Parallel

    finos/legend-engine

    Runs 2 to 30 Pure functions or tests concurrently on the warm LSP daemon via pure-lsp execute-parallel, or every test in a package or .pure file with --package/--source.

    113 GitHub stars~927 tokensUpdated today
    DatabasesAuto-check passed
  • Snowflake

    adobe/skills

    Use this when converting an AI-generated static HTML page (Stardust, Mobirise, Relume, Lovable, v0, Figma-derived, etc.) into an Edge Delivery Services page while preserving the original design and…

    197 GitHub stars~3.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Schema Design Interviewer

    PrepLabsAI/InterviewMentor

    A Data Warehouse and Lakehouse Schema Design Expert interviewer focused on dimensional modeling, star/snowflake schemas, analytics optimization, and modern lakehouse architectures.

    112 GitHub stars~8.2k tokensUpdated 4 days ago
    DatabasesAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Snowflake Native App Release Sheriff

What does Snowflake Native App Release Sheriff do?

Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything. Snowflake Native App Release Sheriff is an agent skill from jeremylongshore/tons-of-skills-marketplace. Preflight Snowflake Native App package releases from trusted, privacy-safe provider evidence without publishing, upgrading, altering, granting, or approving anything.

When should I use Snowflake Native App Release Sheriff?

Snowflake Native App Release Sheriff fits situations like: reviewing manifest/setup safety; security-scan gates; version and release-directive validation; privilege changes.

How do I install Snowflake Native App Release Sheriff in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-native-app-release-sheriff -a claude-code`. Or copy the skill folder (skills/.curated/snowflake-native-app-release-sheriff in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/snowflake-native-app-release-sheriff in your project. Claude Code loads it when a task matches its description.

How do I install Snowflake Native App Release Sheriff in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-native-app-release-sheriff -a codex`. Or copy the skill folder (skills/.curated/snowflake-native-app-release-sheriff in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/snowflake-native-app-release-sheriff in your project. Codex loads it when a task matches its description.

Can I use Snowflake Native App Release Sheriff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-native-app-release-sheriff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/snowflake-native-app-release-sheriff, .gemini/skills/snowflake-native-app-release-sheriff, .github/skills/snowflake-native-app-release-sheriff and .opencode/skills/snowflake-native-app-release-sheriff in your project.

What does Snowflake Native App Release Sheriff need to run?

Going by SKILL.md and its folder, Snowflake Native App Release Sheriff needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*). Compatibility (from SKILL.md): Model-agnostic; Python 3.10+; optional Snowflake CLI for live provider-side read-only collection.

Does Snowflake Native App Release Sheriff access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Snowflake Native App Release Sheriff safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Snowflake Native App Release Sheriff use?

Snowflake Native App Release Sheriff is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Snowflake Native App Release Sheriff use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Snowflake Native App Release Sheriff?

Skills that share tags, products or a category with Snowflake Native App Release Sheriff: Snowflake Development (sickn33/agentic-awesome-skills, 47k stars), Caspian Discord (TryCaspian/caspian-sdk, 973 stars), Write Script Snowflake (windmill-labs/windmill, 18k stars) and Pure Lsp Execute Parallel (finos/legend-engine, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Snowflake Native App Release Sheriff?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.