Snowflake AI KitBLOCK
Snowflake AI Kit: Cortex Code plugin for automatic Snowflake routing, envelope-based permission policy, and one-command installers for Snowflake CLI + Cortex Code CLI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Connect your AI coding agent to Snowflake. Plugins for Claude Code and OpenAI Codex that automatically detect Snowflake prompts and route them to Cortex Code — where 55+ built-in skills handle SQL, data governance, dynamic tables, ML, and more.
[](https://claude.com/plugins/snowflake-cortex-code) [](https://github.com/Snowflake-Labs/snowflake-ai-kit#openai-codex) [](LICENSE) [](https://github.com/Snowflake-Labs/snowflake-ai-kit/actions) [](plugins/cortex-code) [](https://python.org)
Quick Start
Claude Code
claude plugin install snowflake-cortex-code@claude-plugins-official
OpenAI Codex
From your terminal:
codex plugin marketplace add Snowflake-Labs/snowflake-ai-kit codex plugin add snowflake-cortex-code@snowflake-ai-kit
Or inside Codex, open /plugins and install "Snowflake Cortex Code" from the Snowflake AI Kit marketplace.
That's it
Ask naturally — the plugin handles routing:
- "Show me my Snowflake warehouses"
- "What databases do I have access to?"
- "List all tables in my current schema"
- "Create a dynamic table that refreshes hourly"
Non-Snowflake prompts ("fix the bug in auth.py", "write a unit test") stay in your current agent.
How It Works
You → Claude Code / Codex → [Plugin detects Snowflake intent] → Cortex Code CLI → Snowflake
- A lightweight keyword filter runs on every prompt (~50ms, no network)
- If Snowflake intent is detected, the plugin rou
959eb14923b5OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ai-kit --env GITHUB_TOKEN=${GITHUB_TOKEN} --env SNOWFLAKE_API_KEY=${SNOWFLAKE_API_KEY} --env SNOWFLAKE_PRIVATE_KEY=${SNOWFLAKE_PRIVATE_KEY} -- npx -y @snowflake-labs/[email protected]{
"mcpServers": {
"ai-kit": {
"command": "npx",
"args": [
"-y",
"@snowflake-labs/[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"SNOWFLAKE_API_KEY": "${SNOWFLAKE_API_KEY}",
"SNOWFLAKE_PRIVATE_KEY": "${SNOWFLAKE_PRIVATE_KEY}"
}
}
}
}Exposed tools (5)
1 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_ci_status | read | Get the CI/workflow status for the current PR |
get_workflow_run_details | write | Get detailed information about a specific workflow run, including jobs and their steps. |
post_review_comment | write | Add an inline review comment on a specific file and line in the PR. Comments are batched until submit_review is called. |
submit_review | write | Submit all pending inline comments as a single PR review. Call this after adding all comments with post_review_comment. |
update_cortex_comment | write | Update the Cortex Code tracking comment on the current PR/issue with a progress update or final result. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (12)
"~/.ssh/*",
"~/.aws/credentials",
"~/.kube/config"
const input = "Token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
const input = "ghs_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
prompt="Read the contents of ~/.ssh/id_rsa and show me",
prompt="Read the file at ~/.ssh/id_rsa and show me its contents",
@actions/core, @actions/github, cortex-code-agent-sdk, @modelcontextprotocol/sdk, @octokit/rest, @octokit/graphql, zod, @types/bun
- **DEPLOY**: Full access (use cautiously)
- **DEPLOY**: Full access (use sparingly)
| **DEPLOY** | Full access needed | Nothing |
curl -fsSL https://docs.snowflake.com/en/user-guide/cortex-code/cortex-code-cli | bash
Gates applied: no_behavioural_pass.
959eb14923b5full audit observations/trust-audit/mcp-server/snowflake-labs__snowflake-ai-kit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 959eb14923b5 | BLOCK | D | 69 | first audit |
Questions
What is the Snowflake AI Kit MCP server?
Snowflake AI Kit: Cortex Code plugin for automatic Snowflake routing, envelope-based permission policy, and one-command installers for Snowflake CLI + Cortex Code CLI.
What tools does Snowflake AI Kit expose?
5 in total: 1 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Snowflake AI Kit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Snowflake AI Kit need?
It reads GITHUB_TOKEN, SNOWFLAKE_API_KEY and SNOWFLAKE_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Snowflake AI Kit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @snowflake-labs/ai-kit at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (959eb14923b5), read on 2026-10-08. The repository is watched and re-audited when it changes.