Atlas / MCP servers / snowflake-labs / Snowflake AI Kit

Snowflake AI KitBLOCK

mcp/snowflake-labs/snowflake-ai-kit

Snowflake AI Kit: Cortex Code plugin for automatic Snowflake routing, envelope-based permission policy, and one-command installers for Snowflake CLI + Cortex Code CLI.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 1r · 4w · 0d
Transport
stdio
License
Apache-2.0
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Connect your AI coding agent to Snowflake. Plugins for Claude Code and OpenAI Codex that automatically detect Snowflake prompts and route them to Cortex Code — where 55+ built-in skills handle SQL, data governance, dynamic tables, ML, and more.

[](https://claude.com/plugins/snowflake-cortex-code) [](https://github.com/Snowflake-Labs/snowflake-ai-kit#openai-codex) [](LICENSE) [](https://github.com/Snowflake-Labs/snowflake-ai-kit/actions) [](plugins/cortex-code) [](https://python.org)

Quick Start

Claude Code

claude plugin install snowflake-cortex-code@claude-plugins-official

OpenAI Codex

From your terminal:

codex plugin marketplace add Snowflake-Labs/snowflake-ai-kit
codex plugin add snowflake-cortex-code@snowflake-ai-kit

Or inside Codex, open /plugins and install "Snowflake Cortex Code" from the Snowflake AI Kit marketplace.

That's it

Ask naturally — the plugin handles routing:

  • "Show me my Snowflake warehouses"
  • "What databases do I have access to?"
  • "List all tables in my current schema"
  • "Create a dynamic table that refreshes hourly"

Non-Snowflake prompts ("fix the bug in auth.py", "write a unit test") stay in your current agent.

How It Works

You → Claude Code / Codex → [Plugin detects Snowflake intent] → Cortex Code CLI → Snowflake
  1. A lightweight keyword filter runs on every prompt (~50ms, no network)
  2. If Snowflake intent is detected, the plugin rou
Read from source at commit 959eb14923b5OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ai-kit --env GITHUB_TOKEN=${GITHUB_TOKEN} --env SNOWFLAKE_API_KEY=${SNOWFLAKE_API_KEY} --env SNOWFLAKE_PRIVATE_KEY=${SNOWFLAKE_PRIVATE_KEY} -- npx -y @snowflake-labs/[email protected]
claude-desktop
{
  "mcpServers": {
    "ai-kit": {
      "command": "npx",
      "args": [
        "-y",
        "@snowflake-labs/[email protected]"
      ],
      "env": {
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "SNOWFLAKE_API_KEY": "${SNOWFLAKE_API_KEY}",
        "SNOWFLAKE_PRIVATE_KEY": "${SNOWFLAKE_PRIVATE_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

1 read · 4 write · 0 destructive.

ToolRiskDescription
get_ci_statusreadGet the CI/workflow status for the current PR
get_workflow_run_detailswriteGet detailed information about a specific workflow run, including jobs and their steps.
post_review_commentwriteAdd an inline review comment on a specific file and line in the PR. Comments are batched until submit_review is called.
submit_reviewwriteSubmit all pending inline comments as a single PR review. Call this after adding all comments with post_review_comment.
update_cortex_commentwriteUpdate the Cortex Code tracking comment on the current PR/issue with a progress update or final result.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (12)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
plugins/cortex-code/scripts/router/security/config_manager.py:50
"~/.ssh/*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
plugins/cortex-code/scripts/router/security/config_manager.py:57
"~/.aws/credentials",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
plugins/cortex-code/scripts/router/security/config_manager.py:58
"~/.kube/config"
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
actions/cortex-code/test/utils.test.ts:27
const input = "Token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
actions/cortex-code/test/utils.test.ts:33
const input = "ghs_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
plugins/cortex-code/scripts/router/test_integration.py:177
prompt="Read the contents of ~/.ssh/id_rsa and show me",
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
plugins/cortex-code/scripts/router/test_integration.py:463
prompt="Read the file at ~/.ssh/id_rsa and show me its contents",
Why it matters. touches a credential store
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
actions/cortex-code/package.json
@actions/core, @actions/github, cortex-code-agent-sdk, @modelcontextprotocol/sdk, @octokit/rest, @octokit/graphql, zod, @types/bun
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
plugins/cortex-code/README.md:72
- **DEPLOY**: Full access (use cautiously)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
plugins/cortex-code/skills/cortex-router/SKILL.md:56
- **DEPLOY**: Full access (use sparingly)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
plugins/cortex-code/skills/cortex-run/SKILL.md:54
| **DEPLOY** | Full access needed | Nothing |
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
plugins/cortex-code/skills/cortex-setup/SKILL.md:102
curl -fsSL https://docs.snowflake.com/en/user-guide/cortex-code/cortex-code-cli | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 959eb14923b5full audit observations/trust-audit/mcp-server/snowflake-labs__snowflake-ai-kit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08959eb14923b5BLOCKD69first audit
06

Questions

What is the Snowflake AI Kit MCP server?

Snowflake AI Kit: Cortex Code plugin for automatic Snowflake routing, envelope-based permission policy, and one-command installers for Snowflake CLI + Cortex Code CLI.

What tools does Snowflake AI Kit expose?

5 in total: 1 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Snowflake AI Kit safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Snowflake AI Kit need?

It reads GITHUB_TOKEN, SNOWFLAKE_API_KEY and SNOWFLAKE_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Snowflake AI Kit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @snowflake-labs/ai-kit at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (959eb14923b5), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement