clssck/coco-bundled-skills
Snowflake Cortex Code (CoCo) bundled skills, redistributed with written permission from Snowflake.
Debug authorization and permission issues in Snowflake. Use when: access denied, insufficient privileges, permission errors, role issues, missing grants, privilege analysis, least-privilege role creation, find authorizing roles. Triggers: access denied, insufficient privileges, permission error, authorization failed, can't access, missing permission, grant needed, role recommendation, SQL access control error, does not exist or not authorized, EXPLAIN_PRIVILEGES, SYSTEM$ANALYZE_ROLE_ACCESS, SYSTEM$SUGGEST_ROLE_GRANTS.
Semantic View, Semantic Model, Cortex Analyst, and Cortex Agent skill. Use for ALL requests that mention these — including create, build, edit, deploy, validate, audit, optimize, evaluate, suggest VQRs/relationships, or manage verified queries. Keywords: semantic view, semantic model, Cortex Analyst, Cortex Agent, analyst YAML, semantic YAML, analyst model, VQR, verified query, verified query representation, agentic optimization, optimize agent, improve agent accuracy, production-ready agent, sql_correctness, SQL generation accuracy, audit semantic view, suggest relationships, suggest metrics, suggest filters, agent alias, agent version, importing Tableau workbooks (.twb/.twbx/.tds/.tdsx), importing Power BI files (.pbit/.pbix), importing OSI (Open Semantic Interchange, also known as Ossie) YAML models. DO NOT attempt these operations manually — this is the entry point.
Make a listing or data share AI-Ready. Use when: creating semantic views for listings, creating cortex agents for data shares, making data AI-ready. Triggers: AI-ready listing, share agent, data share semantic view, marketplace AI.
Build Snowflake-native document and file pipelines with Cortex AI functions. Turn a plain-language request into an incremental pipeline (stream → task → INCREMENTAL dynamic tables) from a use-case template or a custom composition of building blocks — ingest files from a stage and keep the outputs fresh as new files land. Composes one-off AI steps as part of building a pipeline. Routes to AI_EXTRACT (structured fields), AI_PARSE_DOCUMENT (full text/OCR), AI_COMPLETE (visual/chart/diagram analysis), AI_CLASSIFY (categorize/triage). Use when: building a document/file processing pipeline, an incremental ingestion pipeline over a stage, or an enterprise-search / corpus-intelligence / structured-extraction / customer-360 pipeline. Triggers: document pipeline, build a pipeline, incremental pipeline, ingestion pipeline, keep outputs fresh, process new files as they land, stream and task, dynamic tables, enterprise search, corpus intelligence, structured extraction, customer 360, invoice-processing pipeline, contract analysis at scale. For a one-off task over files you already have — a single file or a one-time batch with no ongoing pipeline: extract, parse/OCR, classify, or visually analyze — use the document-intelligence skill. For standalone AI functions over already-tabular text or image rows with no file, stage, or document, defer to cortex-ai-function-studio.
Measure AI readiness for this Snowflake account. Scores Consumption-Ready (CR) tables, Semantic View (SV) coverage and quality, and demand coverage. Generates an HTML scorecard report with recommendations. Runs in Snowsight (notebook) or CLI mode (direct SQL), auto-detected by environment. Caches results for fast reruns. Use when: AI readiness, readiness score, how AI-ready am I, measure my ai readiness, semantic view coverage, Semantic View (SV) quality, Consumption-Ready (CR) tables, demand coverage, CR tables, AI readiness report, score my account.
Snowflake alert management - create, alter, suspend, resume, and troubleshoot alerts. Use when: user wants to create a new alert, modify an existing alert, set up monitoring, suspend or resume alerts, or investigate why an alert is firing/failing/not delivering. Triggers: create alert, new alert, add alert, alter alert, modify alert, change alert, suspend alert, resume alert, monitor with alert, set up alert, alert condition, troubleshoot alert, debug alert, investigate alert, alert firing, alert failed, alert not firing, why did my alert trigger, CONDITION_FAILED, ACTION_FAILED, notification not delivered.
Attach AI products to Snowflake shares. Use when: adding semantic views, cortex agents, or cortex search services to a share. Triggers: share semantic view, share agent, share cortex search. Invoke this skill to add AI products to a share as a step of sharing AI products or creating a listing to share an AI product.
Schedule recurring Cortex Code runs as Snowflake AGENT TASKs via the cortex automation CLI (aka /automation): daily/hourly/weekly tasks, recurring reports, unattended cron jobs, and checking automation fire history. NOT the LangGraph Cortex Automations product (see cortex-automations).
Org-level Snowflake billing in dollars/currency. Use for: dollar spend by service type, monthly spend trends, which services cost the most money, remaining balance, contract termination date, contract expiration date, contract start date, contract details, rate comparison, reconciliation. Consumption invoices: ODSS_INVOICE_DOCUMENTS, outstanding invoice, overdue invoice, unpaid invoice. Not for credit-based analytics (cost-intelligence) or warehouse DDL (warehouse). Key distinction: dollars/currency → billing, credits only → cost-intelligence.
Create and manage Business Ontology nodes, domains, relationships, and Snowflake object associations — individually or via bulk import with AI extraction. Also owns source registration: track stage files and prefixes as ontology sources, run imports from them, and expose those sources to Cortex Sense for enrichment.
Find certified data products that can answer a user's question and guide the user through using them. Searches Snowflake objects with Snowscope, classifies results by certification (SNOWFLAKE.CORE.CERTIFICATION_STATUS = 'CERTIFIED') and by access (accessible vs Discover-Not-Access), presents a grouped menu, then queries the chosen object. Use this skill whenever a data question is combined with a restriction to certified or trusted sources — for example "use certified data only", "use only certified tables", "from certified sources only", "answer using certified data", "only trusted data", "only governed data", "with certified data in <db.schema> only". Also use when the user asks: "which certified tables can I use for <topic>", "find certified data for my question", "what trusted data is available for <topic>", "is there a certified source for <metric>", "discover certified data products", "answer with certified data only". Do not use for publishing new data products (that is collaboration/data-products) or for cross-account sharing (that is collaboration/data-sharing).
Apply, verify, and manage the SNOWFLAKE.CORE.CERTIFICATION_STATUS tag on Snowflake objects to mark them as trusted sources in the data catalog. Triggers: certify this table, mark as certified, apply certification, tag as trusted, mark this object as certified, certify it. Use when: user wants to mark a specific Snowflake object as certified.
**[REQUIRED]** Use for ALL Snowflake AI function operations — running, authoring, or estimating cost for any AI_* function. **Must be invoked before writing any AI_SENTIMENT, AI_COMPLETE, AI_CLASSIFY, AI_SUMMARIZE_AGG, AI_EXTRACT, AI_FILTER, AI_TRANSLATE, AI_EMBED, AI_PARSE_DOCUMENT, AI_REDACT, AI_TRANSCRIBE, AI_SIMILARITY, or AI_COUNT_TOKENS SQL.** Also covers custom AI function creation, evaluation, and optimization. Triggers: run AI_SENTIMENT, use AI_COMPLETE, AI_CLASSIFY, AI_SUMMARIZE_AGG, AI_EXTRACT, AI_FILTER, AI_TRANSLATE, AI_EMBED, AI_PARSE_DOCUMENT, AI_REDACT, AI_TRANSCRIBE, AI_SIMILARITY, estimate tokens, count tokens, AI function cost, how many tokens will this use, token estimate, sentiment analysis, classify text, extract from text, filter rows, summarize text, analyze data with AI, explore AI functions, unstructured data, custom ai function, build my own llm function, evaluate ai function, optimize ai function, BYOM, bring your own model, SPCS inference, which AI function, built-in AI function, cortex function.
Load this skill when users ask about Cortex Code capabilities, CoCo features, available commands, tools, settings, shortcuts, how to use the CLI, what CoCo can do, CLI reference, keyboard shortcuts, slash commands, configuration options, skill management, agent types, MCP setup, special syntax triggers, hook events, or any question about Cortex Code functionality
MUST consult whenever any command needs a credential, secret, API key, token, or password — whether discovered from an error, source code, --help output, or any other signal. MUST also consult when the user shares, pastes, or includes a secret value directly in their message. Also use when: the user asks about /secrets, storing credentials, secret scopes, or consent modes. Triggers: secret, secrets, /secrets, API key, credential, token, password, authentication, unauthorized, 401, 403, forbidden, EACCES, permission denied, access denied, missing key, invalid token, auth error, connection refused, login failed, .env, environment variable, env var, keychain, export SECRET, cortex secret list, inline secret injection, pasted secret, shared secret, my key is, my password is, my token is, here is my, use it to.
Set up, test, query, and refine Cortex Sense contexts, and turn a built context into a CoWork agent. CoCo runs a background scan of the account the moment the use case is named, proposes a scoped domain context, accepts edits in plain English, and persists a manifest the offline build consumes. Use when: starting a new use case for Cortex Sense, validating a built context with real questions, querying across multiple contexts, listing all available Cortex Sense domains, correcting a wrong / missing / stale answer, recording a correction to a wrong answer (work in progress), or creating an agent grounded in a context. Triggers: set up cortex sense, build cortex sense for <use case>, test the <use case> context, query about <X>, search contexts for <X>, search across contexts for <X>, what does cortex sense know about <X>, which of my contexts know about <X>, refine cortex sense, the agent picked the wrong table, DAU is wrong, exclude staging, add another schema, @cortex-sense resume <use case>, @cortex-sense query <use case> about <X>, list cortex sense, show all domains, what cortex sense do I have, list all contexts, what domains exist, record feedback, log a correction, give feedback on <domain>, create an agent for <domain>, create a cowork agent, deploy <domain> as an agent, add cortex sense to <agent>, enable cortex_sense on <agent>.
Account-level cost analytics via SNOWFLAKE.ACCOUNT_USAGE. Credit usage by warehouse, user, service. Budgets, spending limits, custom budgets. Quotas, per-user spending limits, per-user credit caps, quota notifications, quota enforcement, exclude users from quota, quota shared resources. Resource monitors, suspend triggers. Anomaly detection, anomaly monitors, tag-based anomaly monitoring, costs, chargeback, storage, serverless, containers, data transfer, top user spend, query cost grouping. Cortex AI cost or usage including Cortex Agents, Snowflake Intelligence, Snowflake CoWork, AI function, Cortex Code, CoCo, Cortex Search, Cortex Analyst, Cortex REST API, model training/fine-tuning, and provisioned throughput. Cost insights, waste reduction, savings. Not for org-wide currency spend or multi-account billing (billing/organization-management) or warehouse DDL (warehouse).
Use for ALL requests related to Snowflake Data Clean Rooms (DCR): clean room, cleanroom, DCR, collaboration(s), view/list collaborations, join/review collaboration, invitation, data offering(s), template(s), register, share table, run analysis, run activation, audience overlap, activation, export segment, create collaboration, create cleanroom, measure overlap, manage templates, add template, remove template, approve template, reject template, auto-approval, link data offering, unlink data offering, share data with runner, revoke data access, link local data offering, unlink local data offering, tear down, leave, drop collaboration, delete collaboration, RBAC, DCR roles, DCR privileges, create roles for clean rooms, assign DCR privileges, grant collaboration privileges, revoke DCR privileges, set up DCR roles, privileges for data engineers, privileges for campaign manager, create registry, custom registry, new registry, list registries, view registries, manage registries, create template, write template, build template, template spec, create DCR template, author template, Jinja template, template logic, incrementality measurement, multi-touch attribution, attribution analysis, convert PnC template, migrate template. Covers browsing, joining, registering, running analysis/activation, creating collaborations, managing templates, managing data offerings, RBAC/role setup, leaving/tearing down collaborations, creating/authoring template specs, and creating/listing custom registries via the DCR Collaboration API.
**[REQUIRED]** for Snowflake requests about controlling, protecting, or governing data. Use for sensitive-data discovery or classification; policies, tags, and other protection controls; access or compliance evidence; ownership and stewardship; governance or observability maturity; and policy recommendations. Invoke when users want to find or label sensitive data, prevent exposure, inspect where a policy is attached, determine whether tags follow derived or cloned objects, understand what survives clone, swap, or rename operations, assess coverage across a schema or database, or remediate missing controls. Also use for customer language such as lock it down, restrict, hide, redact, mask, confidential, restricted or tiered data, people below should not see it, finding who can access data or who accessed it, or cleaning up roles. Cover grants, privileges, permissions, role hierarchy and inheritance, least privilege, service-account or agent/app scoping, offboarding, access revocation, excessive access, and insufficient privileges. Do not answer governance-risk tasks from general knowledge. Route incorrect, missing, stale, duplicate, or inconsistent values to data-quality. Route origin, provenance, dependencies, blast radius, and what-will-break questions to lineage. Keep data-governance as coordinator when quality or lineage supplies evidence for a broader governance outcome.
Monitor, analyze, and enforce data quality using Snowflake DMFs. Schema-level and per-table DMF attachment, health scoring, incident investigation, circuit breakers, data quality notifications (expectation/anomaly email and webhook), table comparison, dataset popularity, ad-hoc assessment, prompt quality scoring, and per-group monitoring via WITHIN GROUP clause.
Snowflake secure data sharing: create direct shares, external marketplace listings, debug grant failures. Triggers: create share, share data, share table, share database, outbound share, data sharing, share with account, direct share, external listing, marketplace listing, debug share, share not working, grant failed, consumer can't access, share troubleshooting, why can't they see my data, share error, permission denied on share, share external data, share iceberg table, iceberg data sharing, share S3 data, share Azure data, share GCS data, share without moving data, data outside snowflake, iceberg listing, move data to snowflake and share, replicate and share, openflow and share, load data then share, reshare imported database, reshare incoming data, reshare from listing, reshare ULL, reshare data I received, reshare from ORGDATACLOUD, share data from imported database. WHEN TO USE THIS SKILL: - User wants to share data (generic intent — will ask who they want to share with) - User wants to create direct shares with specific accounts - User wants to create external listings (Snowflake Marketplace) - User wants to reshare data they received from another account (imported DB or ULL) - User needs to debug why a share isn't working WHEN TO USE org-listing workflow INSTEAD: - User mentions "internal marketplace", "organization listing", or "data product" - User wants to share within their Snowflake organization
ONLY for dbt projects deployed INTO Snowflake as native objects via the snow dbt CLI, OR for authoring dbt models using Snowflake-native features (e.g., semantic_view materialization via dbt_semantic_view package). NOT for normal dbt development. Invoke ONLY when the user explicitly mentions: snow dbt commands (deploy, execute, list), EXECUTE DBT PROJECT SQL, a deployed dbt project object (e.g., DB.SCHEMA.MY_PROJECT), ALTER/DROP/DESCRIBE/SHOW DBT PROJECT SQL, scheduling a deployed dbt project with CREATE TASK, generating documentation/catalog/lineage for a deployed project, OR authoring Snowflake-specific dbt materializations (semantic_view, dbt_semantic_view), OR adding a semantic view to an existing dbt project. Do NOT invoke for standard dbt workflows: dbt run, dbt build, dbt test, dbt seed, dbt init, dbt compile, dbt debug, dbt snapshot, dbt deps, dbt clean, dbt retry, dbt ls, profiles.yml, dbt_project.yml, model editing, source freshness, Jinja/macro development, CI/CD pipelines, or any dbt command run from a terminal. The key distinction: this skill is about dbt-as-a-Snowflake-object (snow dbt deploy), not dbt-as-a-CLI-tool (dbt run). Triggers: snow dbt, snow dbt deploy, snow dbt execute, snow dbt list, EXECUTE DBT PROJECT, deployed dbt project, ALTER DBT PROJECT, DROP DBT PROJECT, DESCRIBE DBT PROJECT, SHOW DBT PROJECTS, VERSION$, external-access-integration, dbt project object, migrate, prepare for snowflake, docs generate deployed, documentation deployed project, data catalog deployed, lineage deployed project, generate documentation for deployed, semantic_view materialization, dbt_semantic_view, semantic view in dbt project, add semantic view to dbt, dbt project semantic view, analytical access dbt project.
Use for **ALL** requests that mention: create, build, set up, debug, fix, troubleshoot, optimize, improve, evaluate, or analyze a DCM project. This is the **REQUIRED** entry point - even if the request seems simple. DO NOT attempt to create DCM projects manually or search for DCM documentation - always invoke this skill first. This skill guides users through creating, auditing, evaluating, and debugging workflows for DCM (Database Change Management) projects. Triggers: DCM, DCM project, Database Change Management, snow dcm, manifest.yml with DEFINE, infrastructure-as-code, three-tier role pattern, database roles, DEFINE TABLE, DEFINE SCHEMA.
Data-as-a-product sharing via APPLICATION PACKAGE with TYPE=DATA (data apps). Bundles data with code objects — notebooks, UDFs, stored procedures, Cortex Agents, semantic views — plus versioning and app roles; the consumer installs once with no setup script, and their private data is not accessible. Use when the user explicitly wants declarative sharing or a data app, or to convert/combine existing data shares into a declarative share, or when a consumer migrates from a data share to a declarative app. NOT for open-ended or comparison questions ("is there an alternative to creating shares", "what are my options", "which should I use", "manifests or native apps") and NOT for generic 'share data' requests where the construct is unspecified — those go to the sharing router for disambiguation. Triggers: declarative sharing, declarative share, data app, data application, application package TYPE=DATA, convert share to declarative, migrate share to app, generate manifest from share, introspect share to yaml, combine shares into app, merge multiple shares, versioned share, future-proof share, consumer migrate from share to app, drop-in replacement for share
Deploy containerized apps to Snowpark Container Services. Use when: deploying Docker apps, creating SPCS services, pushing images to Snowflake registry, granting role access to SPCS service endpoints. Triggers: SPCS, Snowpark Container Services, deploy to Snowflake, container deployment, grant access to service, grant role access, service role, consumer access, SPCS service, service endpoints.
Use for Streamlit development tasks with a Snowflake angle: Snowflake-connected dashboards, Streamlit-in-Snowflake (SiS) deployment to warehouse / SPCS / Workspaces, applying Snowflake branding, st.connection('snowflake'), troubleshooting a local streamlit run against Snowflake (wrong role/user/database, 'Database not authorized', PAT-bound USE ROLE failure, stale st.connection cache), and operating an already-deployed STREAMLIT object (ALTER STREAMLIT SET QUERY_WAREHOUSE, RENAME, DROP, GRANT, SHOW STREAMLITS). Also use for general Streamlit authoring (widgets, layouts, caching, theming, custom components) — this skill routes general OSS questions to version-matched content from a detected Streamlit ≥1.57 install, or to a bundled OSS snapshot when no install is available. Triggers: streamlit, st., dashboard, app.py, theme, beautify, style, CSS, color, background, button, custom component, st.components, snowflake dashboard, monitor snowflake, streamlit on snowflake, streamlit in snowflake, SiS, scaffold, snowflake theme, st.connection snowflake, snow streamlit deploy, deploy this streamlit, redeploy, alter streamlit, show streamlits, drop streamlit, rename streamlit app, change query warehouse, streamlit app down, streamlit run wrong role, database not authorized, SNOWFLAKE_DEFAULT_CONNECTION_NAME.
Document intelligence over files, PDFs, images, and stage documents with Snowflake Cortex AI functions — extract fields, parse/OCR text, classify by type, and visually analyze charts/diagrams, for a single file or a one-time batch. Also fine-tunes arctic-extract for domain-specific extraction. Use when: extracting structured fields from PDFs/forms/invoices, parsing or OCR-ing a document, classifying/triaging documents by type, analyzing a chart/blueprint/engineering drawing, or any one-off AI task over files already on a stage. Triggers: extract from PDF, extract fields, extract data from files, structured extraction, parse document, read document, get text from PDF, extract text from image, OCR, scan, digitize, classify documents, categorize files, sort documents, triage files, document type, invoice, contract, receipt, form, blueprint, drawing, engineering drawing, technical drawing, diagram, schematic, chart, graph, plot, my files, my documents, files on stage, AI_EXTRACT, AI_PARSE_DOCUMENT, AI_CLASSIFY, AI_COMPLETE vision, fine-tune, fine-tuning, custom model, train arctic-extract, improve extraction accuracy, FINETUNE. To build a document pipeline — chaining multiple AI functions into one flow, or keeping outputs fresh as new files land (stream → task → dynamic tables) — use the ai-functions-pipeline-builder skill instead.
**[REQUIRED]** Use for **ALL** Snowflake Dynamic Table operations: creating, optimizing, monitoring, troubleshooting, and pipeline diagnostics. This is the required entry point for any dynamic table related tasks (DT is an acronym for dynamic table). Triggers: dynamic table, data pipeline, incremental pipeline, DT pipeline, incremental refresh, target lag, UPSTREAM_FAILED, refresh failing, full refresh instead of incremental, DT health, create DT, debug DT, pipeline timeline, Gantt chart, why was DT skipped, trace pipeline, critical path, why was DT skipped, dbt to DT, convert dbt to dynamic table, dbt dynamic table, dbt materialized dynamic_table.
Apply Snowflake-emitted recommendations to a specific dynamic table. Triggers: apply DT recommendations, apply recommendations to dynamic table, look at recommendations for, RECOMMENDATIONS column, AUTO_RESOLVED_TO_FULL_REFRESH, QUALIFY_RANK_NOT_TOP_LEVEL, TOP_LEVEL_AGGREGATE_NOT_TOP_LEVEL, QUALIFY_RANK_KEYS_NOT_PERSISTED, TOP_LEVEL_AGGREGATE_EXPRESSIONS_NOT_PERSISTED, EXPENSIVE_ORDER_DEPENDENT_WINDOW_FUNCTION, NON_MONOTONIC_GROUPING_KEY, HIGH_BASE_TABLE_CHANGES, CHANGED_BASE_TABLES_UNDER_JOIN, WAREHOUSE_TOO_SMALL, ICEBERG_BASE_TABLE_V2_TO_V3.
Assess, enable, monitor, and manage Error Tables (DML Error Logging) across your Snowflake account. Use when: error tables, error logging, ERROR_TABLE, DML errors, which tables should I enable, which tables have error logging, analyze errors, error table storage, error table retention, clean up errors, monitor errors, error table health, error table report, set up alerting, failed DML queries, string truncation, NOT NULL violation, numeric overflow, check constraint violation, constraint failed.
Manage Snowflake event tables and telemetry configuration. Use when: viewing/configuring event tables, checking telemetry setup, getting/setting telemetry levels, querying event table data, understanding telemetry formats. Triggers: event table, get event table, show event table, current event table, event table setup, event table configuration, telemetry, telemetry setup, telemetry configuration, telemetry levels, get telemetry, show telemetry, check telemetry, log level, trace level, metric level, logging setup, tracing setup, observability setup, event table format, telemetry format, log format, trace format, metric format.
Find, add, check, or update Cortex Code catalog skills and plugins before using them. Use when the user asks to search "the catalog" (even without specifying skill or plugin), discover available skills or plugins, install a catalog skill or plugin, try to find a skill or a plugin that can help with a task, make an uninstalled /skill or $skill usable, search the skill or plugin marketplace/catalog, check whether installed skills or plugins have updates, or update skills and plugins from the catalog, stage, GitHub, or tarball sources. ALSO use when the user expresses intent to acquire, install, or enable a capability, tool, or integration that no already-installed skill covers — even without naming a skill, plugin, or catalog, and including non-Snowflake developer domains such as infrastructure, CI/CD, and third-party SaaS. Do not use this for public Snowflake Marketplace datasets or apps; use marketplace-search for third-party data/product listings.
Present a focused, recommendation-first write-up of ONE Snowflake Marketplace listing (data share, native app, connected app, private/targeted, or request-only): why it fits the user's need, how it's delivered, how they get access, and how its data/capabilities solve the problem. Invoke this skill whenever the user asks you to describe, summarize, write up, explain, review, or give a recommendation on a single listing referenced by title or global name — e.g. "tell me about GZ2FQZ711TU", "give me a detailed write-up of this listing", "what's in the Consumer Pricing listing", "who's behind it / what do they offer", "should I get this listing". ALWAYS invoke it even when the listing metadata is already in the conversation or the user says they "already pulled the details" and pasted the SYSTEM$BULK_GET_LISTINGS or data-dictionary payload: this skill governs how to SHAPE and present that data into the required recommendation format, not just how to retrieve it, so pre-supplied data does NOT make it optional — a raw metadata dump or a generic overview is the wrong output. Do NOT use it for marketplace search results spanning multiple listings — use marketplace-listing-formatting instead.
Guides through CoCo /guardrails and Restricted Session Scope (RSS). Use for ANY request involving: creating a scope, creating an RSS scope, blocking roles for the agent, making the session read-only via RSS, applying a session restriction, storing a scope to the session, removing RSS from a session, deactivating RSS, turning off guardrails, disabling RSS mid-session, preserving session state when removing RSS, 'block securityadmin', 'sql read-only scope', 'restrict what the agent can do', 'limit agent SQL', 'create USER$<USERNAME>.RSS', 'apply scope', 'activate scope', 'how do I use guardrails', 'set up RSS', 'create RSS object', 'named scopes', 'restrict roles for the agent', 'guardrails not working', 'RSS help', 'session scope', 'RESTRICTED_SESSION_SCOPE', 'remove RSS', 'keep session variables', 'keep temp tables after removing RSS'. ALSO use for ANY SQL error whose message contains 'Restricted session scope' — e.g. 'Insufficient privileges to operate on schema. Restricted session scope:'. When this error appears, do NOT suggest role switches or GRANT statements; instead read the active scope via SYS_CONTEXT and guide the user to activate a scope with the required privilege via /guardrails. When a user says "create a scope that blocks X" or "apply read-only to session" or "store scope to session" — always use this skill before doing anything else. Do NOT search external docs for RSS syntax — all syntax is embedded in this skill. Do NOT run cortex search docs for RSS or DDL questions; always use the DDL reference section in this skill instead.
**[REQUIRED]** for ALL creation, updating, or editing of .html files, regardless of complexity. Snowflake renders report HTML in a strict, sandboxed environment: no inline event handlers, no eval, no runtime network calls, no remote images or CDN scripts — only a fixed set of vendored libraries served from /libs/. Author every report to these rules so it renders correctly and is safe to share. Must use whenever generating, creating, updating, or modifying an .html file (e.g. 'update the HTML report at …').
Use for **ALL** Iceberg table requests in Snowflake. This is the **REQUIRED** entry point for creating Iceberg tables (Snowflake-managed storage by default), catalog integrations, catalog-linked databases, external volumes, auto-refresh issues, Horizon IRC diagnostics, Snowflake Intelligence, and converting externally managed tables to Snowflake-managed. DO NOT work with Iceberg manually - invoke this skill first. Triggers: iceberg, iceberg table, apache iceberg, create iceberg table, alter iceberg table, snowflake-managed iceberg, snowflake managed storage, internal storage iceberg, catalog integration, REST catalog, glue, AWS glue, glue IRC, s3 tables, lake formation, unity catalog, databricks, polaris, opencatalog, onelake, microsoft fabric, fabric, fabric lakehouse, onelake REST, biglake, biglake metastore, bigquery metastore, google cloud iceberg, gcp iceberg, lakehouse iceberg rest catalog, workload identity federation, token exchange catalog integration, SAP, SAP BDC, SAP Business Data Cloud, delta sharing, databricks delta sharing, query delta sharing tables, bearer token catalog integration, connect to delta sharing server, CLD, catalog-linked database, auto-discover tables, sync tables, external volume, storage access, S3, Azure blob, GCS, ALLOW_WRITES, storage permissions, auto-refresh, stale data, refresh stuck, delta direct, snowflake intelligence, horizon IRC, horizon IRC setup, horizon REST catalog, PAT authentication horizon, convert to managed, take ownership of iceberg table, externally managed to managed.
Create, replace, alter, drop, describe, and show Snowflake integrations. Covers API, catalog, external access, notification, security, and storage integration types. Use when the user wants to manage integrations or asks about integration SQL commands.
Create organizational listings to share data products via Internal Marketplace. Triggers: create data product, share to internal marketplace, publish to internal marketplace, share to other accounts, share with other accounts, organization listing, org listing, share across accounts, internal marketplace, cross-account sharing, share my agent to other accounts. WHEN TO USE THIS SKILL: - User wants to share with OTHER ACCOUNTS → Use this skill - User mentions "internal marketplace" or "data product" (even for same account) → Use this skill WHEN TO USE RBAC INSTEAD (not this skill): - User wants to share with roles in SAME account only - User does NOT mention "internal marketplace" or "data product" or "listing" - Example: "share this table with ANALYST role" → Use GRANT, not this skill WHEN NOT TO USE THIS SKILL: - User wants to migrate an EXISTING direct share to an org listing → Use the direct-share-to-org-listing-migration skill instead - User wants to migrate an EXISTING personalized listing to an org listing → Use the personalized-listing-to-org-listing-migration skill instead - User wants to migrate an EXISTING private data exchange (PDX) listing to an org listing → Use the pdx-listing-to-org-listing-migration skill instead KEY: If user says "share via internal marketplace" or "as a data product" even for same-account roles, use this skill. Otherwise, same-account = regular RBAC grants.
Use for **ALL** requests that mention Tri-Secret Secure, customer-managed key operations, or periodic data rekeying in Snowflake. Handles CMK status checks, registration, activation (standard, Postgres, private connectivity), deactivation, key rotation, change history, and periodic data rekeying. DO NOT attempt TSS, CMK, or periodic rekeying operations manually - invoke this skill first. Triggers: tri-secret secure, TSS, CMK, BYOK, encryption key, key rotation, CMK history, activate CMK, deactivate CMK, periodic rekeying, periodic data rekeying, PERIODIC_DATA_REKEYING, data rekey, enable rekeying, disable rekeying.
Snowflake table/column lineage: impact analysis, root cause, data discovery, provenance, trust. Triggers: 'what depends on', 'what will break', 'blast radius', 'who uses', 'deprecate', 'before I change', 'affected users', 'downstream', 'cascade', 'root cause', 'trace upstream', 'where does this come from', 'feeds this table', 'sources of', 'column lineage', 'where does [column] come from', 'what uses [column]', 'trace [column]', 'is this trustworthy', 'which table should I use', 'recommend dataset', 'provenance', 'certify', 'verify source'. Also handles questions where users mention external systems (Power BI, Tableau, Sigma, Looker, dbt) — on accounts meeting either of two conditions (Horizon Catalog connectors (Private Preview) enabled, or GET_LINEAGE on a version supporting OpenLineage-sourced entities), lineage results from native-anchored queries automatically include external entities. For value-level data quality (wrong values, failing DMFs) use the data-quality skill first, then this skill to trace upstream. Always read reference/snowflake-apis.md before writing GET_LINEAGE SQL — it has the correct namespace, argument order, and output column names. When external entities appear in results, see reference/external-row-output.md.
**[REQUIRED]** For **ALL** data science and machine learning tasks. This skill should ALWAYS be loaded in even if only a portion of the workflow is related to machine learning. Use when: analyzing data, training models, deploying models to Snowflake, registering models, working with ML workflows, running ML jobs on Snowflake compute, model registry, model service, model inference, log model, deploy pickle file, experiment tracking, model monitoring, gateway A/B testing, ML observability, tracking drift, model performance analysis, distributed training, XGBoost, LightGBM, PyTorch, DPF, distributed partition function, many model training, hyperparameter tuning, HPO, compute pools, train at scale, feature store, feature views, entities, training datasets, online features, pipeline orchestration, DAG, task graph, schedule training, datasets, dataset versioning, DataConnector, ML lineage, model lineage, GET_LINEAGE, trace lineage, forecast, forecasting, time series, anomaly detection, outlier, predict, predictions, backtest, classify, classification, regression, clustering, build a model, create a model, sklearn, scikit-learn, tensorflow, ML, mlops, ray, GPU, deep learning, neural network, explain model, SHAP, Shapley, feature importance, model explainability, interpret model, preprocessing, preprocessor, scaling, encoding, imputation, normalize, transform data before training, preprocessing pipeline. Routes to specialized sub-skills.
Use for requests about Snowflake authentication policies. Create, modify, view, attach, detach, drop, OR recommend authentication policies. Covers: restricting authentication methods (PASSWORD, SAML, OAUTH, KEYPAIR), enforcing MFA, configuring PAT expiry and network policy, workload identity federation, client type restrictions, minimum driver versions, and security integration controls. Invoke when user mentions: authentication policy, auth policy, MFA policy, MFA enrollment, PAT policy, client types, workload identity, driver version policy, keypair only, SAML only, require MFA, block password login, restrict client access, service account authentication, show/list authentication policies, recommend/suggest authentication policies, help me set up auth policies, audit my authentication, harden authentication, lock down authentication.
Manage the end-to-end lifecycle of the Snowflake and SAP BDC Zero-Copy Integration and connector. Use when: consuming SAP data products in Snowflake, publishing Snowflake databases to SAP BDC with minimal CSN (v1.0, SDK-compatible), analyzing shared SAP data, or troubleshooting SAP BDC connector issues. This version uses MINIMAL CSN generation only (no options, no reviews, no validation loops). Triggers: SAP BDC, SAP connector, minimal CSN, SDK CSN, zerocopy connector, SAP data product, SAP BDC Connect, SAP publish, SAP share, SAP troubleshoot.
**[REQUIRED]** Provider onboarding for Snowflake Marketplace. Use for ALL requests about listing, sharing, or distributing data products on the Snowflake Marketplace — including datasets, native apps, DSNA, connected apps, CKE (Cortex Knowledge Extensions), Cortex Agents, and semantic views. Also use for: provider profiles, listing reviews, pricing plans, monetization, Cortex AI Ready status, moving listings between accounts, private sharing via Marketplace, secure shares behind listings, listing access types. This skill OVERRIDES native-app-provider, declarative-sharing, data-sharing, and sharing when the context is Marketplace distribution. For AI object execution this skill DELEGATES to ai-data-share and attach-ai-products-to-share. Triggers: provider onboarding, become a provider, create profile, provider profile, list on marketplace, publish listing, marketplace listing, create listing, share dataset on marketplace, build native app for marketplace, DSNA marketplace, connected app marketplace, CKE marketplace, publish CKE, cortex agent marketplace, publish cortex agent, semantic view marketplace, attach semantic view to listing, AI ready listing, Cortex AI Ready, which AI product type, private share no listing, secure share behind listing, create secure share, move listing between accounts, who reviews my listing, listing review process, email dataset, pricing plans marketplace, paid listing, free to paid listing, listing access types, trial listing, personalized listing, compliance badges, image tile requirements, improve discoverability, provider playbook, invoice status, payout status, update published listing, remove published listing, CKE inside native app, native vs connected app.
Search the Snowflake Marketplace (public, internal, or both) for datasets, data shares, Native Apps, and Connected Apps.
**MANDATORY.** Call skill(command="marketplace-search") before any marketplace search — even if you already know the query or loaded this skill earlier. If you are about to type cortex search marketplace, you must have called skill() first: going straight to bash skips the query-construction and presentation rules and is a defect. Re-invoke once per distinct marketplace need, not for the search you are already running.
Use when the user wants to find, use, or obtain a third-party or internal data product, app, connector, or data share: bare brand names, data categories ("weather data", "ESG and sustainability data", "where can I find email data"), risk, compliance and firmographic profiles ("best source of AML risk data"), connectors and apps ("Salesforce connector", "managed MCP servers", "MCP servers in Snowflake"), availability asks ("is there a connector for X"), marketplace exploration ("most downloaded listing"), alternate-source and best-source asks, catalog-shaped asks that name a vendor, and intra-org listings ("internal listings for HR data", "what is my org publishing for this topic"). The word "external" in a query (e.g. "external job-boards") is enough by itself. Prefer over-firing over missing a marketplace opportunity.
**Bare tokens.** A bare recognizable product, vendor, fund, or brand name alone is enough — "Tomorrow.io", "Fishbowl", "DV360", "Citadel", "Maximo" — including single lowercase words, fragments, and catalog-shaped framings like "what's the snowflake database for salesforce cases?" or "find me a table about X". Invoke in the same turn; do not wait to see whether the internal catalog has it. If you cannot tell whether a token names a company or product, assume it does and search. The only exclusion is a token that reads as a person's given + family name ("give details for daniel spark") or an opaque identifier with no brand reading — a data-domain word next to a vendor ("Person data from Maximo") is not a person name.
**A catalog miss is not an answer.** cortex search object returning nothing is not evidence the data is unavailable. Before you say "I don't have that data", "no objects found", or "you'll need to bring your own data", search the marketplace. An active Snowflake connection is not a reason to treat an ask as catalog-only. When a query names a third-party brand, product, or external source, run both searches in the same turn.
**Mid-conversation.** If the user is about to build against an external source, search the marketplace first — once per data need. This applies even if they named an external source or connector, since the same data is frequently available as a listing; surrounding workflow or sandbox context does not cancel the signal. Once that topic has been searched, a source chosen, or they are iterating on integration code, do not re-pitch unprompted. Always fire on an explicit search request, and re-fire when they ask for more options or pivot to a new data topic.
Do not use for: a listing referenced by global name or exact title (use get-marketplace-listing-details); formatting results already in hand; Snowflake product docs or how-tos (use cortex search docs); specific-value or identifier lookups ("what is the [metric/ID] for [entity]", "what is the SM ID for…"); named-mechanism integration how-tos ("how to use MCP to connect to Salesforce"); educational deep-dives; org-specific business conventions such as a fiscal month calendar or internal cost centres (unless a vendor is named, e.g. Workday); or a data need already resolved earlier in the conversation. Industry-standard code sets and public reference data — CPT, NAICS, postcode-to-lat/long — do fire.
Migration and conversion of databases, SQL, stored procedures, DDL, ETL/integration workloads into Snowflake. Uses Snowflake migrations plugin, including SnowConvert-based code conversion. ALWAYS invoke this skill — DO NOT answer source-vendor SQL questions directly — for: (1) any Snowflake equivalent of non-Snowflake SQL, even simple syntax questions single statements (T-SQL MERGE / sp_send_dbmail, Oracle CONNECT BY / SYSDATE / DUAL / DBMS_OUTPUT, MySQL ON DUPLICATE KEY UPDATE); (2) decommissioning, sunsetting, replatform, lift-and-shift, or modernization of a legacy data warehouse / ETL stack — even when 'Snowflake' isn't named yet (3) any request to convert source code to Snowflake, even if one-off. Triggers: migrate, migration, into snowflake, snowconvert, conversion report, unsupported objects, PL/SQL, plsql, T-SQL, Transact-SQL, tsql, SQL Server, MSSQL, SSMS, MySQL, BigQuery, Redshift, Netezza, SSIS, Informatica, CDC, data migration, data validation, migration testing, decommission, sunset, replatform, modernize, consolidate, legacy data warehouse.
**[REQUIRED]** for ALL Snowflake Native App consumer tasks: installing apps from listings as a consumer, configuring installed apps (granting privileges, approving specifications, reviewing references), managing maintenance policies, understanding native app cost and credit usage, adding native apps to budgets, diagnosing and fixing agent and MCP server issues (caller grants, feature policies, role delegation), uninstalling apps. Triggers: native app, install native app, configure native app, approve spec, decline spec, maintenance policy, maintenance window, upgrade schedule, control upgrades, app cost, app budget, app spending, native app cost, native app credits, how much does my app cost, uninstalling apps, dropping apps, remove app, drop application, app-created agent not working, app agent issues, app MCP issues, caller grants for app, GRANT CALLER to app, fix agent in app, diagnose app agent, configure agent in app, app-created MCP not working, grant caller to application, app MCP configuration.
Use for **ALL** Snowflake Native App Framework tasks: creating app packages, writing manifest files, writing setup scripts, sharing data, testing, versioning, publishing, configuring telemetry and health status reporting, monitoring app health and lifecycle events, setting up event sharing, and debugging apps. Also use for **ALL** SPCS (Snowpark Container Services) work within native apps: adding containers, upgrading container services, building and pushing images, writing service specs, configuring compute pools, and managing service lifecycle. This is the **REQUIRED** entry point for any native app work. DO NOT attempt native app development manually - invoke this skill first. Triggers: native app, app package, application package, manifest.yml, setup script, CREATE APPLICATION, Snowflake marketplace, listing, native app framework, build native app, walk me through, guide me, get started, add version, register version, add patch, release channel, release directive, publish app, publish version, upgrade consumers, telemetry, health status, SYSTEM$REPORT_HEALTH_STATUS, log_level, trace_level, event definitions, event sharing, APPLICATION_STATE, lifecycle events, monitor app, debug app, observability, add streamlit, streamlit dashboard, add dashboard, streamlit UI, add UI to native app, native app streamlit, streamlit frontend, get_active_session, default_streamlit, SPCS native app, container native app, native app containers, native app SPCS, add containers, container_services, grant_callback, specification file, version_initializer, restricted caller, RCR, restricted callers rights, EXECUTE AS RESTRICTED CALLER, GRANT CALLER, caller rights, caller grants, restricted_callers_rights, access consumer data, consumer's role, caller's privileges, consumer's privileges, add agent, cortex agent in app, app-created agent, CREATE AGENT, CREATE MCP SERVER, CREATE CUSTOM MCP SERVER, MCP server native app, agent tools, test agent in app, DATA_AGENT_RUN, app agent, app MCP server.
Recommend, evaluate, and migrate Snowflake network policies using built-in security procedures. Use when: generating network policy recommendations from access history, evaluating candidate policies before deployment, migrating existing policies to use Snowflake-managed SaaS rules, creating hybrid policies combining custom rules with SaaS rules. Triggers: recommend network policy, evaluate network policy, candidate policy, migrate policy, SaaS rules, hybrid policy.
Router for Snowflake notification skills. Routes to integration creation/management, content formatting, or sending. Triggers: notification, notification integration, email notification, webhook, slack, teams, pagerduty, send notification, notification content.
Openflow data integration operations. Openflow is a Snowflake NiFi-based product for data replication and transformation. Use for connector deployment, configuration, diagnostics, and custom flows.
Troubleshoot Openflow connector / runtime / deployment issues via Snowsight SQL diagnostics, and run a narrow set of confirmation-gated SQL actions on SQL-managed runtimes. Use when: connector is unhealthy, table FAILED, runtime stuck or OOM, EAI / network issues, restart / resume / suspend runtime, attach EAI to runtime. Triggers: openflow, connector, runtime, deployment, EAI, table FAILED, openflow troubleshoot, openflow runtime.
Snowflake organization management — accounts, org users, org insights, org spending, org security, globalorgadmin. ORGANIZATION_USAGE views, cross-account analytics, org-wide metrics. Use when the user asks about: 30 day summary of my organization, 30-day summary, 30 day summary, accounts in my organization, list accounts, how many accounts, account editions, account regions, account inventory, organization users, organization user groups, executive summary of my org, org overview, org spending, org cost, org security posture, org reliability, org auth posture, org hub, org usage views, trust center, MFA readiness, login failures, warehouse credits, storage trends, edition distribution, who has globalorgadmin, what is globalorgadmin, globalorgadmin role, orgadmin role, organization administrator, org admin, enable orgadmin, disable orgadmin, org admin permissions, account admins, ORGANIZATION_USAGE, org-level, cross-account, org-wide.
Score and rank candidate Snowflake objects on trust signals to identify the most trustworthy source for a user's data question. Trust signals include: semantic view backing (including verified queries), dashboard/Streamlit dependency usage, daily refresh patterns, service role ownership, schema placement, freshness, and structural quality. Triggers: which table should I use, score these tables, rank these objects, which is most trustworthy, best source for, which table has, what is the best data to use for. Use when: candidates have already been identified and the user needs to know which one is the most trustworthy source for a given metric or concept.
Desktop/CLI environment for building Snowflake Apps in CoCo Desktop on a local machine with a full shell, the snow CLI, and npm. Load this alongside the snowflake-apps skill for ANY Snowflake App request on the desktop: create, scaffold, build, develop, run locally, deploy, publish, operate, monitor, or troubleshoot. A Snowflake App is a web application (typically Next.js) deployed to SPCS via snow app — NOT a Streamlit app or Native App. Triggers: build me an app, new app, scaffold, web app, dashboard, data app, deploy my app, push to snowflake, ship it, deploy failed, run locally, develop, app logs, app status, app.yml, app.yml v2, snowflake.yml, snow app setup, snow app deploy --target, snowflake-app.
Comprehensive Snowflake security investigation and threat detection. Use for: login anomalies, IP analysis, brute force detection, impossible travel, data exfiltration, bulk exports, unauthorized sharing, privilege escalation, RBAC violations, suspicious grants, backdoor accounts. This is the REQUIRED entry point for all security investigations. Routes to specialized sub-skills for focused analysis.
Set up Single Sign-On (SSO) for Snowflake with your Identity Provider (IdP). Supports Microsoft Entra ID (Azure AD), Okta, and other SAML 2.0 providers including OneLogin, Ping Identity, Google Workspace, Auth0, Duo, JumpCloud, and more. Includes advanced scenarios: Allowed Interfaces, Auto Redirect, and Snowflake Intelligence tile setup.
Share or unshare a local skill or plugin to users within the same account by executing the Cortex Extension share SQL directly. Use when the user says "share skill", "publish skill", "share my skill", "share plugin", "publish plugin", "share my plugin", "share with users", "share publicly", "upload to cortex extension", "publish my skill", "publish my plugin", "make available", "add to skill catalog", "add to catalog", "add skill to catalog", "add plugin to catalog", "add my skill to the catalog", "publish to skill catalog", "publish to the catalog", "submit to skill catalog", "put in the skill catalog", "unshare skill", "unshare plugin", "stop sharing", "remove shared", "revoke access", "remove from catalog", "delete from catalog" or "delete shared". This is for publishing a local skill or plugin TO the catalog; to install or pull an existing skill FROM the catalog, use find-skill-and-plugin instead. Does not handle consumer/install flows. Does not handle sharing across accounts.
Router for Snowflake sharing and collaboration. Routes to Secure Data Sharing, Declarative Sharing, Native Apps, or Data Clean Rooms. Asks up to 2 questions when intent is ambiguous, then loads the target sub-skill. This skill should supersede invocation of product-specific skills unless the product is named explicitly — in particular, open-ended or comparison requests (alternatives, options, 'which should I use', 'manifests or native apps') must come here, not to a product skill. Triggers: share, sharing, listing, data product, how do I share, what's the best way to share, compare sharing options, alternative to a share, alternatives to sharing, what are my options for sharing, which sharing option, not sure how to share, manifests or native apps.
Create, document, audit, refactor, or compile skills for Cortex Code. Use when: creating new skills, capturing session work as skills, reviewing skills, refactoring large skills, building a deterministic fast path for a skill. Triggers: create skill, build skill, new skill, summarize session, capture workflow, audit skill, review skill, refactor skill, triage skills, compile skill, speed up skill, programmatic skill, fast path for skill.
Build and deploy web applications on Snowflake. Use for ALL app requests: create, scaffold, build, deploy, publish, develop, test, operate, monitor, or troubleshoot a SAR app (Snowflake App Runtime app, also called a Snowflake App). A SAR app is a web application (typically Next.js) that runs on Snowflake and is represented by an APPLICATION SERVICE object — distinct from Streamlit-in-Snowflake apps and Native Apps. Also load this skill when the user's current directory is a Snowflake App Runtime project: if the directory contains an app.yml file, or if it contains a snowflake.yml file with type: snowflake-app anywhere in it. Also use it for questions about a SAR app's deployment manifest, including which of the two supported layouts a project uses (snowflake.yml plus a build-only app.yml, or a single app.yml with version: 2) and moving between them. Triggers: build me an app, new app, scaffold, web app, dashboard, data app, deploy my app, push to snowflake, ship it, deploy failed, fix deploy, run locally, develop, app logs, app status, restart app, app.yml, app.yml v2, app.yml version 2, snowflake.yml, migrate to app.yml, downgrade to snowflake.yml, deployment targets, default_target, --target, snowflake-app-runtime, snowflake-app, application service, show application services, alter application service.
**[REQUIRED]** Use for **ALL** Snowflake Interactive Table and Interactive Warehouse operations. Triggers: interactive table, interactive warehouse, low-latency queries, high-concurrency dashboard, TARGET_LAG for interactive.
Create and edit Workspace notebooks (.ipynb files) for Snowflake. Use when: creating workspace notebooks, editing notebooks, debugging notebook issues, converting code to notebooks, multi-step workflows that combine SQL queries with Python code execution and visualization, step-by-step data analysis requiring both SQL and Python, interactive data exploration with code and charts. Do NOT use for: static SQL-only dashboards (use dashboard skill), Streamlit apps, standalone Python scripts, or stored procedures. Triggers: notebook, .ipynb, snowflake notebook, workspace notebook, create notebook, edit notebook, jupyter, ipynb file, notebook cell, SQL cell, step-by-step analysis with SQL and Python, data exploration with code and visualization, combine SQL and Python.
**[REQUIRED]** Use for **ALL** requests involving Snowflake Postgres, and for general help working with any PostgreSQL database through standard PG tooling (psql, ~/.pg_service.conf, ~/.pgpass, pg_doctor diagnostics). Triggers: 'postgres', 'postgresql', 'pg', 'psql', 'create postgres instance', 'show postgres instances', 'suspend postgres', 'resume postgres', 'reset postgres credentials', 'rotate postgres password', 'import postgres connection', 'postgres network policy', 'postgres health check', 'pg_doctor', 'pg_lake', 'postgres iceberg', 'pg iceberg', 'read pg_lake in snowflake', 'pg to snowflake iceberg', 'catalog integration for pg_lake', 'expose pg_lake to snowflake', 'SNOWFLAKE_POSTGRES catalog', 'catalog linked database for pg_lake', 'query postgres iceberg from snowflake', 'postgres slow queries', 'cache hit', 'bloat', 'vacuum', 'dead rows', 'postgres locks', 'blocking queries', 'postgres disk usage', 'active postgres queries', 'postgres connection count', 'neon', 'supabase', 'rds postgres', 'aurora postgres', 'azure postgres', 'crunchy bridge', 'external postgres', 'my postgres', 'migrate postgres', 'pg migration', 'postgres to snowflake', 'logical replication setup', 'pg_dump migration', 'migration assessment', 'cutover plan', 'rollback plan', 'migrate from RDS', 'migrate from Aurora', 'migrate from Azure postgres', 'migrate from Cloud SQL', 'move my postgres', 'transfer postgres', 'CREATE_MIRROR', 'LIST_MIRRORS', 'managed mirror', '$live', '$changes'. Do NOT use for generic Iceberg / catalog integration / storage integration / data lake requests — those are owned by the iceberg skill, EXCEPT for catalog integrations scoped to pg_lake (CATALOG_SOURCE = SNOWFLAKE_POSTGRES), which are handled here. Only handle Iceberg when it is scoped to pg_lake (Postgres-resident Iceberg tables or the pg_lake-specific catalog integration path).
Publish a local HTML report file as a shareable Snowflake Intelligence (Cowork) report artifact from Cortex Code. Copies the HTML into the user's workspace (an editable copy) and creates the report artifact linked back to it, so the "edit" button opens the workspace copy. Use after authoring an HTML report, or whenever the user asks to publish or share one. Triggers: publish report, publish the html, publish this report, share report, publish to snowflake intelligence, publish to cowork, share to cowork, publish as a snowflake intelligence / cowork report.
**[REQUIRED]** Use for **ALL** Snowflake Task operations: creating, scheduling, managing, monitoring, and troubleshooting tasks and task graphs. This is the required entry point for any task-related work. Triggers: task, tasks, scheduled task, cron task, task graph, DAG, task chain, task pipeline, triggered task, stream trigger, WHEN condition, SYSTEM$STREAM_HAS_DATA, suspend task, resume task, alter task, drop task, task history, task failure, auto-suspended, SUSPEND_TASK_AFTER_NUM_FAILURES, serverless task, finalizer task, task permissions, EXECUTE TASK, task schedule, task monitoring, parameterized task, CONFIG, SYSTEM$GET_TASK_GRAPH_CONFIG, runtime parameters, configurable pipeline, return value, pass data between tasks, SYSTEM$SET_RETURN_VALUE, SYSTEM$GET_PREDECESSOR_RETURN_VALUE, inter-task communication.
MANDATORY for Snowflake workspace operations. Workspace lifecycle (CREATE/ALTER/DROP/RENAME), file MOVEMENT (upload, download, list, remove, copy) via the cortex ws CLI subcommand, RBAC (GRANT READ/WRITE), shared-workspace publishing (ALTER WORKSPACE ... COMMIT to make uploads visible to other users), dropped-user recovery (DROPPED_USER$), replication setup, account-wide audit. Git-backed (git-synced) workspaces are a PRIVATE workspace connected to a git repo: they are created ONLY in the Snowsight UI (Projects » Workspaces » From Git repository) — there is no CREATE WORKSPACE DDL/CLI for them; a shared workspace CANNOT be git-backed (collaborate via each user's own git-backed workspace + git push/pull, not RBAC grants); and there is no reliable public way to tell whether a workspace is git-backed via SQL/CLI (DESCRIBE/SHOW WORKSPACES don't report it — check in the Snowsight UI). Use when the user uploads, downloads, lists, removes, or copies files in a Snowflake workspace; creates/alters/drops a workspace; shares or revokes access; recovers content from a dropped user; sets up workspace replication; or asks anything referencing snow://workspace URIs, USER$ schemas, LOCAL schema workspaces, DEFAULT$/My Workspace, secondary replicas, or workspace administration. Triggers: workspace, workspaces, snow://workspace, USER$, DEFAULT$, personal workspace, shared workspace, git-backed workspace, git-synced workspace, connect workspace to git, LOCAL workspace, ALTER WORKSPACE, GRANT WORKSPACE, list workspace, files in workspace, what's in my workspace, secondary replica, read-only replica, dropped user.
**[REQUIRED]** Use for **ALL** requests involving Snowpark Python — writing pipelines, transforming data, loading files, deploying stored procedures/UDFs, OR observability. MUST invoke this skill even for seemingly simple tasks because Snowflake DataFrame semantics differ from Pandas in ways that silently produce wrong results (NULL handling, division by zero, GREATEST, datediff, type casting). Always load this skill BEFORE writing any Snowpark code. Triggers: Snowpark, Python, DataFrame, pipeline, ETL, ingest, transform, load data, CSV, Parquet, JSON, XML, join, aggregate, window function, UDF, UDTF, UDAF, Stored Procedure, deploy, snow snowpark CLI, DBAPI, JDBC, external database, pull data, event table, logging, tracing, trace events, profiler, debug UDF, debug procedure, observability, telemetry, slow procedure, alert on error, monitor.
**[REQUIRED]** Use for ALL Snowpipe Streaming tasks: setup, configure, troubleshoot, monitor, optimize, or migrate streaming pipelines. Covers the High-Performance Architecture exclusively. Triggers: snowpipe streaming, streaming ingestion, low-latency ingestion, real-time ingestion, Snowpipe Streaming SDK, channel, insertRows, appendRows, streaming channel, PIPE object, streaming pipe, snowpipe v2, high-performance streaming, migrate classic streaming, troubleshoot streaming.
Migrate Spark scripts and notebooks to Snowflake. Routes to one of two bundled conversion paths and orchestrates the post-conversion pipeline. **Default path: Snowpark Connect (SCOS)**, which preserves the PySpark API surface. The SMA / Snowpark API path is invoked only when the user explicitly asks for it. Triggers: convert spark, migrate pyspark, migrate spark, migrate to snowpark, convert to snowpark, snowpark connect, scos, scos migration, migrate to snowpark connect, migrate to scos, snowpark api, sma cli, sma conversion, run sma, snowflake.snowpark rewrite, already migrated, already ran sma, sma dashboard, fix ewis, stage conversion, dvp orchestrator, resume dvp, assess pyspark, assess spark, assess databricks, spark assessment, databricks assessment, spark workload assessment, migration readiness, migration readiness report, spark readiness, spark compatibility, spark compatibility report, pyspark compatibility, pyspark compatibility report, databricks compatibility, databricks to snowflake, pyspark to snowflake, spark to snowflake, spark snowflake, migration feasibility, migration effort, migration effort estimate, migration complexity, migration scope, how hard is migration, how complex is migration, analyze spark, analyze pyspark, analyze databricks, spark analysis, pyspark analysis, workload analysis, pre-migration analysis, spark workload analysis, check spark, check pyspark, check databricks, check compatibility, spark compatibility check, scan spark, scan pyspark, spark audit, audit spark, review spark, understand spark, understand pyspark, understand databricks, evaluate spark workload, should I migrate to snowflake, can my spark run on snowflake, snowflake readiness, spark migration scope, scope the migration.
Use for ANY task that writes, fixes, runs, or debugs Snowflake SQL. Especially use when the user provides a failed query, a Snowflake SQL error, asks to repair SQL, asks for data from tables/views, or needs query validation.
Create, manage, and monitor Snowflake storage lifecycle policies. Use when: creating expiration or archival policies, attaching policies to tables, monitoring policy execution, retrieving archived data, managing data retention, reducing storage costs, saving on table storage. Triggers: storage lifecycle, lifecycle policy, archive data, expire data, COOL tier, COLD tier, data retention, archival storage, CREATE STORAGE LIFECYCLE POLICY, FROM ARCHIVE OF, ARCHIVE_FOR_DAYS, storage cost optimization, table is large, table is expensive, save on storage.
Multi-phase team orchestration for feature implementation. HIGHEST PRIORITY — load FIRST (before domain skills) when user requests teammates, teams, swarms, parallel agents, or the workflow auto-triggers (/team, cortex --team, ctrl+g).
Use for ALL Snowflake Trust Center requests: security findings, scanner analysis, scanner management, finding remediation, severity distribution, CIS benchmarks, Security Essentials, Threat Intelligence, AI Security, enable/disable scanners, scanner schedules, notifications, webhook, notification integration, at-risk entities, security posture, vulnerability analysis, detection analysis, remediation guidance.
Warehouse configuration, DDL, Gen2, adaptive warehouses, adaptive compute, compute, MAX_QUERY_PERFORMANCE_LEVEL, QUERY_THROUGHPUT_MULTIPLIER, performance tuning, sizing, credit-per-hour rates, resume behavior, region availability, Snowpark-optimized limitations, warehouse conversion, warehouse migration, convert to adaptive, migrate to adaptive, switch to adaptive, analytical workload, analytical queries, analytical pipeline, transformation workload, data loading pipeline, ETL workload, batch processing, warehouse suitability, warehouse fit, good candidate for adaptive, should I use adaptive, is adaptive right, why didn't adaptive work, warehouse spilling, warehouse performance issues, heavy spilling on warehouse, warehouse is slow, which warehouses to migrate. Not for cost analytics or warehouse spend (cost-intelligence) or billing.
Snowflake SQL query execution analysis via ACCOUNT_USAGE views. Triggers: spilling, partition pruning, cache hit rates, clustering keys, search optimization (SOS) candidates, query acceleration (QAS) eligibility, predicate column analysis for clustering/SOS, per-warehouse spill/prune/cache metrics, slow SQL query diagnosis. Not for: cost/credits (cost-intelligence), access audit (data-governance), writing or debugging user SQL.