Agent skill

Snowflake Strong Auth Migration Pilot

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Pilot a Snowflake authentication modernization without lockouts or credential exposure.

MITAuto-check passedDatabases

Install Snowflake Strong Auth Migration Pilot

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-strong-auth-migration-pilot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace snowflake-strong-auth-migration-pilot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/snowflake-strong-auth-migration-pilot .claude/skills/snowflake-strong-auth-migration-pilot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
snowflake-strong-auth-migration-pilot
GitHub stars
2.8k
Token cost
~3k tokens
SKILL.md length
1,186 words
Files
16 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Pilot a Snowflake authentication modernization without lockouts or credential exposure.

  • Works in 7 steps: Read current-evidence-contract.md, → Build one schema-2 bundle containing… → At the controlled local boundary,… → …
  • Replacing Snowflake passwords
  • SKILL.md covers Overview, Prerequisites, Authentication and Non-negotiable boundaries, plus 6 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Snowflake Strong Auth Migration Pilot is an agent skill from jeremylongshore/tons-of-skills-marketplace. Pilot a Snowflake authentication modernization without lockouts or credential exposure. Inventory PERSON, SERVICE, and LEGACYSERVICE users; map named workloads to WIF, key pair, OAuth, or bounded PAT; and audit managed MCP/OAuth session controls. Use when replacing Snowflake passwords, reviewing service identities, planning workload identity federation, or scoping MCP OAuth. Trigger with phrases like "Snowflake auth migration", "service user password", "Snowflake WIF", "key pair rotation", or "MCP OAuth role…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `eval-spec.yaml`, `references/current-evidence-contract.md` and `references/cutover-and-recovery.md`). Compatibility notes: Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection

It sits in Databases, covering Data warehousing and OAuth and OpenID Connect. It works with Snowflake and Model Context Protocol. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Replacing Snowflake passwords
  • Reviewing service identities
  • Planning workload identity federation
  • Scoping MCP OAuth

Example prompts

  • “Snowflake auth migration”
  • “service user password”
  • “Snowflake WIF”
  • “/snowflake-strong-auth-migration-pilot”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read current-evidence-contract.md,
  2. Build one schema-2 bundle containing those receipts, the exact expected
  3. At the controlled local boundary, compute and separately record the final
  4. Run the evidence-gated analyzer with that out-of-band digest
  5. Load mcp-oauth-role-scoping.md when
  6. Produce the dry-run cutover packet. For each workload include owner, current
  7. Require both positive and negative receipts: target login and allowed action;

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection

    From compatibility in the SKILL.md frontmatter.

Context cost

Snowflake Strong Auth Migration Pilot loads about 3k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 1,186 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,186 words, ~2,999 tokens.

Download SKILL.mdSave it as .claude/skills/snowflake-strong-auth-migration-pilot/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
snowflake-strong-auth-migration-pilot
description
Pilot a Snowflake authentication modernization without lockouts or credential exposure. Inventory PERSON, SERVICE, and LEGACY_SERVICE users; map named workloads to WIF, key pair, OAuth, or bounded PAT; and audit managed MCP/OAuth session controls. Use when replacing Snowflake passwords, reviewing service identities, planning workload identity federation, or scoping MCP OAuth. Trigger with phrases like "Snowflake auth migration", "service user password", "Snowflake WIF", "key pair rotation", or "MCP OAuth role scope".
allowed-tools
Read, Bash(python3:*)
compatibility
Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection
argument-hint
[redacted-auth-evidence.json]
version
3.16.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, snowflake, security, authentication, wif, oauth, mcp

Snowflake Strong-Auth Migration Pilot

Overview

Convert an uncertain Snowflake identity estate into an owner-backed, least-privilege authentication pilot. The useful unit is a named workload and its runtime—not a blanket account-wide password deadline. The pilot classifies PERSON, SERVICE, LEGACY_SERVICE, and SERVICE_AGENT principals, maps each bound workload to a supported target, and checks that managed MCP/OAuth primary-role scopes, client behavior, and secondary-role controls cannot silently broaden access.

Prerequisites

  • Three live schema-2 collector receipts: near-current SHOW USERS, delayed Account Usage USERS, and the latency-settled portion of a bounded trailing seven-day LOGIN_HISTORY horizon. Record the final bundle SHA-256 outside the bundle when it crosses the controlled local collection boundary; an embedded self-checksum is not provenance.
  • Named identity/workload owner, security approver, executor, recovery identity, and approved canary/change window. The inventory must include a separately tested break-glass identity and a canary receipt with positive and negative outcomes. Keep those operational receipts outside this posture bundle; the analyzer intentionally rejects and never echoes embedded canary or recovery payloads.
  • Python 3.10+ for the bundled stdlib analyzer. No Snowflake driver or network access is required.

Authentication

This skill's analyzer is offline and intentionally has no credential or token authentication flow. If live Snowflake evidence is collected, use the organization's approved session/authentication process and record method names only; never place credentials in the inventory or report. This skill has no Edit authority and never edits local source or Snowflake objects. The Python analyzer may write only the explicitly requested sanitized report path via --out; never use that capability for credentials or mutation commands.

This package does not provide an MCP server, OAuth client, or token broker. Any connector is configured separately. Supply only sanitized read-only evidence and verify account, edition, connector, client behavior, and feature availability.

Non-negotiable boundaries

  • Read-only planning. This skill never disables users, rotates keys, creates or alters integrations, changes authentication/network policies, or handles passwords, PATs, tokens, private keys, or client secrets.
  • Do not invent a universal retirement date. Dates depend on the account, connector, runtime, feature availability, owner, and approved change window.
  • A service without a named workload is an ownership gap, not permission to disable it. A LEGACY_SERVICE must be bound and tested before retirement.
  • Snowflake-managed SNOWFLAKE_SERVICE rows remain in receipt cap accounting but are excluded from the operator migration denominator. SERVICE_AGENT remains an operator-owned service classification.
  • Prefer WIF only when the exact cloud runtime, Snowflake integration, and connector support it. Otherwise evaluate key pair, OAuth, or a bounded PAT using workload-auth-options.md.
  • Managed MCP/OAuth uses separate controls: advertised primary-role scopes, client scope behavior, the user's DEFAULT_ROLE, allowed/blocked roles, and OAUTH_USE_SECONDARY_ROLES. Never collapse those into one invented role list.

Workflow

  1. Read current-evidence-contract.md, then collect all three independent read-only surfaces under the same account, collector identity, primary role, secondary-role configuration, and CLI profile:

    bash
    AUTH_PROFILE="replace-with-approved-readonly-profile"
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface auth-current --connection "${AUTH_PROFILE}" \
      --output snowflake-auth-current.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface auth --connection "${AUTH_PROFILE}" \
      --output snowflake-auth-history.json
    python3 "${CLAUDE_SKILL_DIR}/scripts/collect_snowflake_evidence.py" \
      --surface auth-login-history --connection "${AUTH_PROFILE}" \
      --output snowflake-auth-login-history.json

    Do not use --input-json: offline normalization cannot bind live posture or execution context. A cap hit, collector error, stale receipt, context mismatch, privilege-filtered SHOW row, or user-hash drift blocks scoped completeness.

  2. Build one schema-2 bundle containing those receipts, the exact expected hashed organization-plus-account/user/role authorization context, an explicit digest coverage denominator, owner-backed users/workloads, and one approved bounded enforcement window per workload. Operator type and current authentication method declarations must match receipted posture. Include method names and booleans only; omit credential values and all canary/break-glass payloads. Workload names must be unique. MFA posture is a separate factor observation, not a primary auth_methods value. The reference defines the exact envelope.

  3. At the controlled local boundary, compute and separately record the final canonical bundle digest:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_auth_evidence.py" \
      --input snowflake-auth-bundle.json --print-input-sha256

    The digest is an operator assertion of byte identity, not a signature or collector identity proof. Never place it inside the bundle it authenticates.

  4. Run the evidence-gated analyzer with that out-of-band digest:

    bash
    python3 "${CLAUDE_SKILL_DIR}/scripts/analyze_auth_evidence.py" \
      --input snowflake-auth-bundle.json \
      --trusted-input-sha256 sha256:<recorded-digest> \
      --out snowflake-auth-pilot.json

    The wrapper validates exact reviewed SQL hashes, sources, dataset fields, row counts/caps, live mode, wall-clock freshness, declared authorization context, coverage, and current/history reconciliation before allowing receipt rows into analysis. analyze_auth.py remains the metadata-only planning engine; it cannot certify evidence.

  5. Load mcp-oauth-role-scoping.md when an MCP/OAuth integration appears. Verify feature support and live role mapping; the report is not evidence that an integration is enabled.

  6. Produce the dry-run cutover packet. For each workload include owner, current path, selected target, capability evidence, role scope, canary, rollback, and the exact authorized operator/change window. Read cutover-and-recovery.md.

  7. Require both positive and negative receipts: target login and allowed action; old-path rejection only after replacement/recovery; out-of-scope role/object denial; and independent recovery. Keep the current path until receipts are accepted.

Show full SKILL.md (450 more words)Show less

Mapping rules

  • PERSON with SSO/OAuth evidence: retain interactive design and verify the IdP path; do not silently convert a human to a service identity.
  • PERSON with password only: high-priority review, not an automatic disable.
  • SERVICE/LEGACY_SERVICE with password/basic: high-priority modernization; choose WIF → key pair → OAuth → PAT only from declared supported options.
  • SERVICE without workload: ownership/inventory finding.
  • Unknown user, runtime, driver, or target capability: MANUAL_REVIEW, not a guessed migration.
  • Missing or untested break-glass identity or canary: block the pilot; do not disable the current path.
  • PAT: bounded fallback only; record owner, audience, revocation/expiration process, and why stronger options are unavailable.

Output

Return a JSON report plus a human-readable packet containing:

  • deterministic input SHA-256 and evidence scope;
  • per-surface trust, freshness, exact-template, cap, and context assessments;
  • current/historical pseudonymous user reconciliation and drift;
  • latency-settled LOGIN_HISTORY observations, explicitly separated from proof;
  • counts and findings for PERSON/SERVICE/LEGACY_SERVICE/SERVICE_AGENT;
  • workload-to-identity-to-auth target mapping and rationale;
  • managed MCP/OAuth integration state, advertised scopes, client/default-role behavior, scope-setting location/object, allowed/blocked roles, secondary-role controls, and mismatches;
  • no-credential safety statement plus narrow analyzer/collector operation boundaries;
  • read-only inventory receipt, explicit edit_authority: false, and separately tested break-glass/canary evidence;
  • positive/negative verification receipts and a recovery plan; and
  • residual unknowns with named owners rather than fabricated certainty.

Error Handling

ConditionResponse
Missing/mismatched out-of-band digestQuarantine receipt rows and return UNTRUSTED, INVALID_TRUST_ANCHOR, or DIGEST_MISMATCH.
SHOW-only, stale, capped, errored, or context-mismatched evidenceBlock scoped completeness and cutover approval; recollect all required surfaces.
Raw username, email, IP, event ID, factor ID, connection ID, or free-form error appears in receipt rowsReject the receipt; use only the reviewed pseudonymous projection.
Credential-bearing field appearsStop; remove it and rerun with metadata only.
Service has no workload/ownerDo not disable it; open ownership discovery.
WIF support is not provenTreat supported_auth as an unverified operator declaration; verify the exact runtime, driver, connector, integration, and target login before approval.
MCP OAuth controls are missing or broadStop; capture scopes, client behavior, default role/warehouse, allow/block lists, and secondary-role mode.
Canary or recovery test failsPreserve the current path, use the approved recovery route, and record the failure.
User requests mass disable/rotationConvert to a staged, owner-approved packet; this skill does not execute mutations.

Examples

Password-backed ETL service

Declare a password-backed ETL_SVC as LEGACY_SERVICE, bind it to etl-prod, and list only supported target methods such as ["WIF", "KEY_PAIR"]. The analyzer selects WIF first, then requires canary login, allowed-action, denied-old-path, and recovery receipts.

Managed MCP/OAuth

Declare OAUTH_SCOPES_SUPPORTED, whether the client requests a named role or session:role:all, the user's DEFAULT_ROLE and DEFAULT_WAREHOUSE, the integration allow/block lists, and OAUTH_USE_SECONDARY_ROLES. A missing or overbroad control stops the packet; the analyzer never broadens it.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (scripts, references) in skills/.curated/snowflake-strong-auth-migration-pilot of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • references/current-evidence-contract.md
  • references/cutover-and-recovery.md
  • references/identity-types-and-inventory.md
  • references/mcp-oauth-role-scoping.md
  • references/workload-auth-options.md
  • scripts/analyze_auth.py
  • scripts/analyze_auth_evidence.py
  • scripts/collect_snowflake_evidence.py
  • scripts/sql/auth-current.sql
  • scripts/sql/auth-login-history.sql
  • scripts/sql/auth.sql
  • tests/fixtures/auth.json
  • tests/test_auth_analyzer.py
  • tests/test_auth_evidence.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Snowflake Strong Auth Migration Pilot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Snowflake Strong Auth Migration Pilot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Snowflake Strong Auth Migration Pilot this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3kAutomated safety check: PassMIT
Setup Snowflakeai-analyst-lab/ai-analyst304—~2kAutomated safety check: NotesMIT
Migrating To Amazon Redshiftaws/agent-toolkit-for-aws2.8k—~2.7kAutomated safety check: NotesApache-2.0
Setup Snowflakeopenshift-eng/ai-helpers120—~1.9kAutomated safety check: NotesApache-2.0
Agent BomLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.0
Clickhouse Best Practicesvemetric/vemetric3952 repos~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Setup Snowflake

    ai-analyst-lab/ai-analyst

    First-time Snowflake setup wizard for the NATIVE ConnectionManager path (the connection the analyst actually queries through, with auto-logged provenance).

    304 GitHub stars~2k tokensUpdated 10 days ago
    DatabasesAuto-check: notes
  • Migrating To Amazon Redshift

    aws/agent-toolkit-for-aws

    Official

    Guides an end-to-end data-warehouse migration to Amazon Redshift — discovery, schema/SQL/stored-procedure/macro/script conversion, data migration, validation, performance comparison, and reporting.

    2.8k GitHub stars~2.7k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Setup Snowflake

    openshift-eng/ai-helpers

    This skill should be used before any Snowflake command to verify MCP connectivity, guide users through access provisioning, and set the session context.

    120 GitHub stars~1.9k tokensUpdated 4 days ago
    DatabasesAuto-check: notes
  • Agent Bom

    LeoYeAI/openclaw-master-skills

    Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Clickhouse Best Practices

    vemetric/vemetric

    MUST USE when reviewing ClickHouse schemas, queries, or configurations.

    395 GitHub starsUsed in 2 repos~2.6k tokens
    DatabasesAuto-check passed
  • Webapp Builder

    sidequery/sidemantic

    Build interactive analytics webapps, demos, dashboards, or embedded app surfaces from Sidemantic semantic models using copyable component primitives and deterministic query inspection.

    129 GitHub stars~5.5k tokensUpdated 4 days ago
    DatabasesAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Snowflake Strong Auth Migration Pilot

What does Snowflake Strong Auth Migration Pilot do?

Pilot a Snowflake authentication modernization without lockouts or credential exposure. Snowflake Strong Auth Migration Pilot is an agent skill from jeremylongshore/tons-of-skills-marketplace. Pilot a Snowflake authentication modernization without lockouts or credential exposure.

When should I use Snowflake Strong Auth Migration Pilot?

Snowflake Strong Auth Migration Pilot fits situations like: replacing Snowflake passwords; reviewing service identities; planning workload identity federation; scoping MCP OAuth.

How do I install Snowflake Strong Auth Migration Pilot in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-strong-auth-migration-pilot -a claude-code`. Or copy the skill folder (skills/.curated/snowflake-strong-auth-migration-pilot in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/snowflake-strong-auth-migration-pilot in your project. Claude Code loads it when a task matches its description.

How do I install Snowflake Strong Auth Migration Pilot in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-strong-auth-migration-pilot -a codex`. Or copy the skill folder (skills/.curated/snowflake-strong-auth-migration-pilot in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/snowflake-strong-auth-migration-pilot in your project. Codex loads it when a task matches its description.

Can I use Snowflake Strong Auth Migration Pilot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill snowflake-strong-auth-migration-pilot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/snowflake-strong-auth-migration-pilot, .gemini/skills/snowflake-strong-auth-migration-pilot, .github/skills/snowflake-strong-auth-migration-pilot and .opencode/skills/snowflake-strong-auth-migration-pilot in your project.

What does Snowflake Strong Auth Migration Pilot need to run?

Going by SKILL.md and its folder, Snowflake Strong Auth Migration Pilot needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*). Compatibility (from SKILL.md): Model-agnostic workflow; requires Python 3.10+; optional Snowflake CLI for live read-only evidence collection.

Does Snowflake Strong Auth Migration Pilot access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Snowflake Strong Auth Migration Pilot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Snowflake Strong Auth Migration Pilot use?

Snowflake Strong Auth Migration Pilot is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Snowflake Strong Auth Migration Pilot use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.

What are the alternatives to Snowflake Strong Auth Migration Pilot?

Skills that share tags, products or a category with Snowflake Strong Auth Migration Pilot: Setup Snowflake (ai-analyst-lab/ai-analyst, 304 stars), Migrating To Amazon Redshift (aws/agent-toolkit-for-aws, 2.8k stars), Setup Snowflake (openshift-eng/ai-helpers, 120 stars) and Agent Bom (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Snowflake Strong Auth Migration Pilot?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.