SnowflakeSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/isaacwasserman-mcp-snowflake-server)
Overview
A Model Context Protocol (MCP) server implementation that provides database interaction with Snowflake. This server enables running SQL queries via tools and exposes data insights and schema context as resources.
Components
Resources
- `memo://insights`
A continuously updated memo aggregating discovered data insights. Updated automatically when new insights are appended via the append_insight tool.
- `context://table/{table_name}`
(If prefetch enabled) Per-table schema summaries, including columns and comments, exposed as individual resources.
Tools
The server exposes the following tools:
Query Tools
- `read_query`
Execute SELECT queries to read data from the database. Input:
query(string): TheSELECTSQL query to execute
Returns: Query results as array of objects
- `write_query` (enabled only with
--allow-write)
Execute INSERT, UPDATE, or DELETE queries. Input:
query(string): The SQL modification query
Returns: Number of affected rows or confirmation
- `create_table` (enabled only with
--allow-write)
Create new tables in the database. Input:
query(string):CREATE TABLESQL statement
Returns: Confirmation of table creation
Schema Tools
- `list_databases`
List all databases in the Snowflake instance. Returns: Array of database names
- `list_schemas`
List all schemas within a specific database. Input:
database(string): Name of the database
Returns: Array of schema names
- `list_tables`
List all tables within a specific database and schema. Input:
database(string): Name of the databaseschema(string): Nam
02c57c9752feOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp_snowflake_server --env SNOWFLAKE_PRIVATE_KEY_PATH=${SNOWFLAKE_PRIVATE_KEY_PATH} -- uvx mcp_snowflake_server{
"mcpServers": {
"mcp_snowflake_server": {
"command": "uvx",
"args": [
"mcp_snowflake_server"
],
"env": {
"SNOWFLAKE_PRIVATE_KEY_PATH": "${SNOWFLAKE_PRIVATE_KEY_PATH}"
}
}
}
}Exposed tools (8)
4 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
append_insight | write | Add a data insight to the memo |
create_table | write | Create a new table in the Snowflake database |
describe_table | read | Get the schema information for a specific table |
list_databases | read | List all available databases in Snowflake |
list_schemas | read | List all schemas in a database |
list_tables | read | List all tables in a specific database and schema |
read_query | write | Execute a SELECT query. |
write_query | destructive | Execute an INSERT, UPDATE, or DELETE query on the Snowflake database |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
write_query
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
02c57c9752fefull audit observations/trust-audit/mcp-server/isaacwasserman__snowflake-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 02c57c9752fe | SAFE | B | 89 | first audit |
Questions
What tools does Snowflake expose?
8 in total: 4 read-only, 3 that write, and 1 that can delete or overwrite (write_query). Every one is listed on this page with its risk.
Is Snowflake safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Snowflake need?
It reads SNOWFLAKE_PRIVATE_KEY_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Snowflake run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp_snowflake_server.
How current is this page?
The grade is for one exact copy of the source (02c57c9752fe), read on 2026-10-06. The repository is watched and re-audited when it changes.