Skip to content

add check-agent-access - #67

Merged
jdanielmyers merged 2 commits into
Snowflake-Labs:mainfrom
martinseifertprojuventute:main
Jul 9, 2026
Merged

jdanielmyers merged 2 commits into
Snowflake-Labs:mainfrom
martinseifertprojuventute:main

Conversation

@martinseifertprojuventute

Copy link
Copy Markdown
Contributor

Skill submission checklist

Before submitting, please confirm the following:

Folder structure

  • [/] My skill lives at skills/<my-skill-id>/
  • [/] The folder name matches the id field in SKILL.md (lowercase, hyphens only)
  • [/] SKILL.md is present in the skill folder
  • [/] LICENSE is present in the skill folder

Frontmatter

  • [/] name field is filled in
  • [/] description field clearly explains what the skill does, when to use it, and what triggers it
  • [/] id field matches the folder name
  • [/] authors field includes the contributor's name
  • [/] type is set to community or snowflake
  • [/] status is set to stable, beta, or draft
  • [/] categories includes at least one relevant tag

License

  • [/] Community contributors: LICENSE is Apache 2.0
  • Snowflake employees: LICENSE is the Snowflake Skills License

Testing

  • [/] I tested this skill in a Cortex Code session against my example prompt
  • [/] The skill behavior matches what is described in the description field

Optional

  • Supporting files (templates, examples) are organized into templates/ or references/ subdirectories
  • [/] checked that my skill name does not conflict with a bundled Cortex Code skill (run /skill in a session to verify)

Describe your skill:

Audits all (or selected) Cortex Agents in a Snowflake account. For each agent the
skill reads the live specification, extracts every dependency (semantic views, Cortex
Search services, UDFs, warehouses, tables), then checks whether a user-supplied role
holds the required privilege on each object — including inherited grants via role
hierarchy. Results are presented as a gap table grouped by agent, followed by an
optional one-click remediation script.

Triggers: check agent access, audit agent privileges, who can use my agents,
role access to agents, missing agent grants, grant agent usage, agent USAGE check,
PUBLIC can't call agent, fix agent permissions, check role permissions for Cortex Agent.

Do NOT use for: general RBAC design (use rbac), warehouse credit audits,
or auditing non-agent Snowflake objects.

Example prompt that triggers it:

Audit which Cortex Agents the PUBLIC role can access and fix any gaps.
Who can use my Cortex Agents?
Check if the READER role is missing any agent grants.

@github-actions

github-actions Bot commented Jul 3, 2026

Copy link
Copy Markdown

Skill Staged to AEM

Skill: check-agent-access

👉 Preview URL: https://publish-p57963-e462098.adobeaemcloud.com/en/developers/skills-library/


Generated by GitHub Actions

@jdanielmyers
jdanielmyers merged commit 1637fb0 into Snowflake-Labs:main Jul 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants