Repository navigation
add check-agent-access - #67
Merged
Merged
Conversation
Skill Staged to AEMSkill: 👉 Preview URL: https://publish-p57963-e462098.adobeaemcloud.com/en/developers/skills-library/ Generated by GitHub Actions |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Skill submission checklist
Before submitting, please confirm the following:
Folder structure
skills/<my-skill-id>/idfield inSKILL.md(lowercase, hyphens only)SKILL.mdis present in the skill folderLICENSEis present in the skill folderFrontmatter
namefield is filled indescriptionfield clearly explains what the skill does, when to use it, and what triggers itidfield matches the folder nameauthorsfield includes the contributor's nametypeis set tocommunityorsnowflakestatusis set tostable,beta, ordraftcategoriesincludes at least one relevant tagLicense
Testing
descriptionfieldOptional
templates/orreferences/subdirectories/skillin a session to verify)Describe your skill:
Audits all (or selected) Cortex Agents in a Snowflake account. For each agent the
skill reads the live specification, extracts every dependency (semantic views, Cortex
Search services, UDFs, warehouses, tables), then checks whether a user-supplied role
holds the required privilege on each object — including inherited grants via role
hierarchy. Results are presented as a gap table grouped by agent, followed by an
optional one-click remediation script.
Triggers: check agent access, audit agent privileges, who can use my agents,
role access to agents, missing agent grants, grant agent usage, agent USAGE check,
PUBLIC can't call agent, fix agent permissions, check role permissions for Cortex Agent.
Do NOT use for: general RBAC design (use
rbac), warehouse credit audits,or auditing non-agent Snowflake objects.
Example prompt that triggers it:
Audit which Cortex Agents the PUBLIC role can access and fix any gaps.
Who can use my Cortex Agents?
Check if the READER role is missing any agent grants.