agent-bom discover snowflake
Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it wit…
Agent Bom
@msaad00
What This Skill Does
Discovers Snowflake Cortex, Snowpark, notebooks, Streamlit apps, MCP endpoints, and AI-observability assets from the operator's Snowflake environment, then emits a canonical agent-bom inventory JSON file. Runs locally using the operator's existing read-only credentials without exposing long-lived secrets to agent-bom.
Replaces manual inventory collection across Snowflake's AI and workload services by automating discovery and outputting a standardized, schema-validated JSON bill of materials.
When to Use It
- Inventory all Snowflake Cortex AI services and models in the account
- List Snowpark sessions, notebooks, and Streamlit apps for audit or migration
- Scan Snowflake MCP endpoints and AI-observability dashboards for compliance
- Generate a canonical agent-bom JSON for Snowflake AI infrastructure before a review
- Discover Snowflake workloads without granting agent-bom long-lived credentials
Install
$ openclaw skills install @msaad00/agent-bom-discover-snowflakeagent-bom-discover-snowflake
Use this skill to collect Snowflake AI and workload inventory as schema-valid agent-bom inventory. Default to discover-only: write JSON to an operator-selected path and stop.
Guardrails
- Use only operator-approved Snowflake accounts, warehouses, databases, and read-only roles.
- Prefer SSO, OAuth, or key-pair auth. Do not request or display
SNOWFLAKE_PASSWORD, private key contents, passphrases, or OAuth tokens. - Do not modify Snowflake resources. This workflow is discovery-only.
- Write inventory only to a path the operator chose.
- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON is the evidence.
Workflow
python examples/operator_pull/snowflake_inventory_adapter.py \
--account "$SNOWFLAKE_ACCOUNT" \
--user "$SNOWFLAKE_USER" \
--authenticator snowflake_jwt \
--source snowflake-skill-invoked \
--discovery-method skill_invoked_pull \
--output snowflake-inventory.json
Scan only when the operator asks for findings:
agent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json
Evidence Contract
The emitted inventory carries discovery_provenance.source_type: skill_invoked_pull, observed_via: skill_invoked_pull, snowflake_sdk,
sanitized metadata.permissions_used, and redacted credential material. If
schema validation fails, stop and fix the inventory instead of scanning a
best-effort summary.
Top skills in this category
Marketing Skills
@jchopard69Access 23 marketing modules offering checklists, frameworks, and ready-to-use deliverables for CRO, SEO, copywriting, analytics, launches, ads, and social me...
Openclaw Command Center
@jontsaiMission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in o...
moltbook-interact
@lunarcmdInteract with Moltbook social network for AI agents. Post, reply, browse, and analyze engagement. Use when the user wants to engage with Moltbook, check their feed, reply to posts, or track their activity on the agent social network.
ClawOps
@okoddcatThe orchestration tool for OpenClaw, managing and coordinating all your skills seamlessly.
Anti-Injection-Skill
@georges91560Detect prompt injection, jailbreak, role-hijack, and system extraction attempts. Applies multi-layer defense with semantic analysis and penalty scoring.