{"id":"b68af8e2-13cd-482d-9782-d8243c588dbc","entityType":"agent","slug":"clawhub-msaad00-agent-bom-discover-snowflake","name":"agent-bom discover snowflake","canonicalUrl":"https://www.xpersona.co/agent/clawhub-msaad00-agent-bom-discover-snowflake","canonicalPath":"/agent/clawhub-msaad00-agent-bom-discover-snowflake","generatedAt":"2026-10-09T20:37:47.347Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":null},"description":"Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Snowflake credentials. Use when a user asks to inventory Snowflake AI or Cortex infrastructure as canonical inventory.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.3K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-snowflake","sourceUrl":"https://clawhub.ai/msaad00/agent-bom-discover-snowflake","homepage":"https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/msaad00/agent-bom-discover-snowflake","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":73,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-bom discover snowflake technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":null},"stars":null,"forks":null,"downloads":4339,"packageName":null,"latestVersion":"0.108.3","tractionLabel":"4.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:33:51.188Z","lastCrawledAt":"2026-10-09T05:33:51.188Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:33:51.188Z","lastVerifiedAt":null,"highlights":[{"version":"0.108.3","createdAt":"2026-10-08T22:19:03.698Z","changelog":"Release v0.108.3","fileCount":3,"zipByteSize":3284},{"version":"0.108.2","createdAt":"2026-10-08T05:02:19.851Z","changelog":"Release v0.108.2","fileCount":3,"zipByteSize":3203},{"version":"0.108.1","createdAt":"2026-10-06T17:48:38.699Z","changelog":"Release v0.108.1","fileCount":3,"zipByteSize":3290},{"version":"0.108.0","createdAt":"2026-10-04T07:13:34.827Z","changelog":"Release v0.108.0","fileCount":3,"zipByteSize":3407},{"version":"0.107.2","createdAt":"2026-10-01T23:33:09.887Z","changelog":"Release v0.107.2","fileCount":3,"zipByteSize":3329},{"version":"0.107.0","createdAt":"2026-09-30T20:19:08.233Z","changelog":"Release v0.107.0","fileCount":3,"zipByteSize":3270},{"version":"0.106.1","createdAt":"2026-09-27T00:19:24.942Z","changelog":"Release v0.106.1","fileCount":3,"zipByteSize":3318},{"version":"0.105.0","createdAt":"2026-09-18T11:12:18.230Z","changelog":"Release v0.105.0","fileCount":3,"zipByteSize":3489}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-snowflake","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173dmtq1jwv3yxcgnmcxnn45583ey2y:agent-bom-discover-snowflake` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/msaad00/agent-bom-discover-snowflake before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T20:37:47.346Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-msaad00-agent-bom-discover-snowflake/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":null},"readme":"Skill: agent-bom discover snowflake\n\nOwner: msaad00\n\nSummary: Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Snowflake credentials. Use when a user asks to inventory Snowflake AI or Cortex infrastructure as canonical inventory.\n\nTags: latest:0.108.3\n\nVersion history:\n\nv0.108.3 | 2026-10-08T22:19:03.698Z | user\n\nRelease v0.108.3\n\nv0.108.2 | 2026-10-08T05:02:19.851Z | user\n\nRelease v0.108.2\n\nv0.108.1 | 2026-10-06T17:48:38.699Z | user\n\nRelease v0.108.1\n\nv0.108.0 | 2026-10-04T07:13:34.827Z | user\n\nRelease v0.108.0\n\nv0.107.2 | 2026-10-01T23:33:09.887Z | user\n\nRelease v0.107.2\n\nv0.107.0 | 2026-09-30T20:19:08.233Z | user\n\nRelease v0.107.0\n\nv0.106.1 | 2026-09-27T00:19:24.942Z | user\n\nRelease v0.106.1\n\nv0.105.0 | 2026-09-18T11:12:18.230Z | user\n\nRelease v0.105.0\n\nv0.104.0 | 2026-09-09T20:57:16.636Z | user\n\nRelease v0.104.0\n\nv0.103.2 | 2026-09-02T07:25:21.031Z | user\n\nRelease v0.103.2\n\nv0.102.0 | 2026-08-24T04:51:12.944Z | user\n\nRelease v0.102.0\n\nv0.101.0 | 2026-08-16T23:14:12.056Z | user\n\nRelease v0.101.0\n\nv0.100.0 | 2026-08-12T20:56:07.887Z | user\n\nRelease v0.100.0\n\nv0.99.0 | 2026-08-06T00:53:44.005Z | user\n\nRelease v0.99.0\n\nv0.98.3 | 2026-08-03T06:09:47.747Z | user\n\nRelease v0.98.3\n\nv0.98.2 | 2026-07-27T08:50:49.849Z | user\n\nRelease v0.98.2\n\nv0.98.1 | 2026-07-27T02:02:50.164Z | user\n\nRelease v0.98.1\n\nv0.98.0 | 2026-07-25T01:52:10.897Z | user\n\nRelease v0.98.0\n\nv0.97.5 | 2026-07-24T01:44:16.569Z | user\n\nRelease v0.97.5\n\nv0.97.4 | 2026-07-23T00:59:59.378Z | user\n\nRelease v0.97.4\n\nv0.97.2 | 2026-07-21T18:19:51.953Z | user\n\nRelease v0.97.2\n\nv0.97.1 | 2026-07-21T03:32:22.944Z | user\n\nRelease v0.97.1\n\nv0.97.0 | 2026-07-20T18:11:32.226Z | user\n\nRelease v0.97.0\n\nv0.96.4 | 2026-07-20T15:06:30.003Z | user\n\nRelease v0.96.4\n\nv0.96.3 | 2026-07-16T04:06:13.888Z | user\n\nRelease v0.96.3\n\nv0.96.2 | 2026-07-15T23:05:55.935Z | user\n\nRelease v0.96.2\n\nv0.95.0 | 2026-07-13T21:39:06.348Z | user\n\nRelease v0.95.0\n\nv0.94.2 | 2026-07-09T18:25:12.765Z | user\n\nRelease v0.94.2\n\nv0.94.1 | 2026-07-09T05:51:25.725Z | user\n\nRelease v0.94.1\n\nv0.94.0 | 2026-07-08T21:48:41.628Z | user\n\nRelease v0.94.0\n\nv0.93.0 | 2026-07-06T07:43:30.574Z | user\n\nRelease v0.93.0\n\nv0.91.0 | 2026-06-30T23:37:03.765Z | user\n\nRelease v0.91.0\n\nv0.90.0 | 2026-06-30T03:48:19.283Z | user\n\nRelease v0.90.0\n\nv0.89.2 | 2026-06-22T03:18:17.938Z | user\n\nRelease v0.89.2\n\nv0.88.5 | 2026-06-01T06:24:17.416Z | user\n\nRelease v0.88.5\n\nv0.88.4 | 2026-05-26T04:20:47.122Z | user\n\nRelease v0.88.4\n\nv0.88.3 | 2026-05-25T00:57:52.974Z | user\n\nRelease v0.88.3\n\nv0.88.1 | 2026-05-22T04:38:51.039Z | user\n\nRelease v0.88.1\n\nv0.87.1 | 2026-05-18T20:26:08.043Z | user\n\nRelease v0.87.1\n\nv0.87.0 | 2026-05-18T00:37:14.472Z | user\n\nRelease v0.87.0\n\nv0.86.5 | 2026-05-11T16:16:22.391Z | user\n\nRelease v0.86.5\n\nv0.86.2 | 2026-05-07T15:45:33.766Z | user\n\nRelease v0.86.2\n\nv0.86.1 | 2026-05-06T06:42:42.580Z | user\n\nRelease v0.86.1\n\nv0.85.0 | 2026-05-02T22:49:06.084Z | user\n\nRelease v0.85.0\n\nv0.84.6 | 2026-05-02T06:44:32.317Z | user\n\nRelease v0.84.6\n\nv0.84.5 | 2026-05-02T03:29:35.119Z | user\n\nRelease v0.84.5\n\nv0.84.4 | 2026-05-01T19:07:58.864Z | user\n\nRelease v0.84.4\n\nv0.84.0 | 2026-05-01T01:53:52.640Z | user\n\nRelease v0.84.0\n\nArchive index:\n\nArchive v0.108.3: 3 files, 3284 bytes\n\nFiles: skill-card.md (1930b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.108.3:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.108.3:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497943698\n}\n\nFile v0.108.3:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets and produces canonical agent-bom inventory for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and Snowflake operators use this skill to inventory Cortex, Snowpark, notebooks, Streamlit, MCP, and AI-observability assets with their own read-only credentials, then optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery uses the operator's Snowflake authentication context.\n\nMitigation: Use only approved accounts and a least-privilege, read-only Snowflake role; do not share credentials in chat.\n\nRisk: Generated inventory may reveal internal Snowflake assets even when credential-like values are redacted.\n\nMitigation: Choose the inventory output path and review the JSON before sharing or scanning it.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Files]\n\n**Output Format:** [Markdown instructions and canonical JSON inventory; optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; scanning is optional and requires an explicit request.]\n\n## Skill Version(s):\n\n0.108.3 (source: frontmatter and server release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.2: 3 files, 3203 bytes\n\nFiles: skill-card.md (1707b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.108.2:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.108.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.108.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.108.2\",\n  \"publishedAt\": 1791435739851\n}\n\nFile v0.108.2:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to inventory Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets using their own read-only access. They can optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery uses the operator's Snowflake authentication context and may read local connection configuration.\n\nMitigation: Use a least-privilege read-only role, keep credentials in the operator environment, and approve the account and output path before running discovery.\n\n## Reference(s):\n\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, JSON inventory, JSON findings]\n\n**Output Format:** [Markdown guidance with shell commands; JSON files at operator-selected paths]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory discovery is the default; findings are produced only on request.]\n\n## Skill Version(s):\n\n0.108.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.1: 3 files, 3290 bytes\n\nFiles: skill-card.md (1941b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.108.1:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.108.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.108.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.108.1\",\n  \"publishedAt\": 1791308918699\n}\n\nFile v0.108.1:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets, writes canonical agent-bom inventory JSON, and optionally scans that inventory for findings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers and Snowflake operators use this skill to inventory approved Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets with read-only access. They can request a local scan of the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery uses the operator's Snowflake authentication context.\n\nMitigation: Use an approved account and read-only role; keep passwords, private keys, and tokens out of chat.\n\nRisk: Generated inventory may contain information about Snowflake assets.\n\nMitigation: Choose the output path yourself and review the inventory before sharing it.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project](https://github.com/msaad00/agent-bom)\n- [agent-bom Python package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance, Files]\n\n**Output Format:** [Markdown guidance and shell commands; JSON inventory and optional JSON scan findings when run]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; scanning is optional and requires an explicit request.]\n\n## Skill Version(s):\n\n0.108.1 (source: skill frontmatter and ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.108.0: 3 files, 3407 bytes\n\nFiles: skill-card.md (2223b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.108.0:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.108.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.108.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.108.0\",\n  \"publishedAt\": 1791098014827\n}\n\nFile v0.108.0:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets, writes canonical agent-bom inventory JSON, and optionally scans that inventory without giving agent-bom long-lived Snowflake credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to inventory Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets with their own read-only credentials. They can optionally scan the resulting inventory for findings when requested.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Snowflake metadata discovery may expose information beyond the intended scope.\n\nMitigation: Use only operator-approved accounts and a least-privilege read-only Snowflake role.\n\nRisk: Inventory files may contain sensitive operational metadata if shared or scanned without review.\n\nMitigation: Choose the output path yourself and review the generated inventory before scanning or sharing it.\n\nRisk: Snowflake authentication material could be exposed during setup.\n\nMitigation: Use an existing operator-managed auth context; do not paste passwords, private keys, or tokens into chat.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom Python package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [JSON inventory, JSON scan findings, Shell commands, Guidance]\n\n**Output Format:** [JSON files and Markdown guidance with shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; findings are produced only when scanning is requested.]\n\n## Skill Version(s):\n\n0.108.0 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.2: 3 files, 3329 bytes\n\nFiles: skill-card.md (2044b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.107.2:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.107.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.107.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.107.2\",\n  \"publishedAt\": 1790897589887\n}\n\nFile v0.107.2:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets using operator-approved read-only access and produces canonical agent-bom inventory JSON for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and Snowflake operators use this skill to inventory Cortex, Snowpark, notebooks, Streamlit, MCP, and AI-observability assets. They can optionally scan the generated inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery accesses a Snowflake account and could expose sensitive inventory details.\n\nMitigation: Use an approved account and least-privilege read-only role; review the inventory before sharing or pushing it.\n\nRisk: Authentication material or an unverified external package could compromise the operator environment.\n\nMitigation: Prefer SSO, OAuth, or key-pair authentication, never paste secrets into chat, and verify the agent-bom package before installation.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project (skill metadata; import provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Guidance]\n\n**Output Format:** [Markdown guidance and shell commands; inventory and optional findings in JSON]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; scanning is optional and requires operator request.]\n\n## Skill Version(s):\n\n0.107.2 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.107.0: 3 files, 3270 bytes\n\nFiles: skill-card.md (1912b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.107.0:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.107.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.107.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.107.0\",\n  \"publishedAt\": 1790799548233\n}\n\nFile v0.107.0:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets and writes canonical agent-bom inventory JSON for optional local scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to inventory Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets using their existing read-only Snowflake access. They can optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery can expose sensitive Snowflake inventory to anyone who receives the output file.\n\nMitigation: Use a least-privilege read-only role and review the generated inventory before sharing it.\n\nRisk: The Snowflake adapter runs from the separately installed agent-bom package, not from this skill file.\n\nMitigation: Review the installed adapter and use only an operator-approved Snowflake account and authentication context.\n\n## Reference(s):\n\n- [Agent-BOM project homepage (skill metadata)](https://github.com/msaad00/agent-bom)\n- [Agent-BOM Python package (skill metadata)](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, JSON inventory files, JSON scan findings, Guidance]\n\n**Output Format:** [Markdown instructions and local JSON files]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is the default output; scan findings are generated only on request.]\n\n## Skill Version(s):\n\n0.107.0 (source: ClawHub release and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.106.1: 3 files, 3318 bytes\n\nFiles: skill-card.md (2081b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.106.1:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.106.1\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.106.1:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.106.1\",\n  \"publishedAt\": 1790468364942\n}\n\nFile v0.106.1:skill-card.md\n\n## Description:\n\nDiscovers Snowflake AI and workload assets and produces canonical agent-bom inventory JSON using operator-controlled, read-only credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to inventory Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets. An optional local scan produces findings when the operator requests it.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery could access more Snowflake data than intended.\n\nMitigation: Use only operator-approved accounts and read-only roles.\n\nRisk: Snowflake credentials or inventory could be exposed.\n\nMitigation: Keep credentials in the operator environment, do not paste secrets into chat, and verify the inventory output path before running.\n\nRisk: Incomplete inventory could produce misleading scan findings.\n\nMitigation: Validate inventory against its schema and scan only when the operator requests findings.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project (skill metadata link; provenance unavailable)](https://github.com/msaad00/agent-bom)\n- [agent-bom package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, JSON inventory]\n\n**Output Format:** [Markdown guidance and commands; canonical inventory JSON when executed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Discovery writes to an operator-selected path; an optional scan can produce JSON findings.]\n\n## Skill Version(s):\n\n0.106.1 (source: server release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.105.0: 3 files, 3489 bytes\n\nFiles: skill-card.md (2394b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.105.0:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.105.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.105.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.105.0\",\n  \"publishedAt\": 1789729938230\n}\n\nFile v0.105.0:skill-card.md\n\n## Description:\n\nDiscovers Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emits canonical agent-bom inventory JSON, and can scan it on request without giving agent-bom long-lived Snowflake credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and platform engineers use this skill to inventory Snowflake AI and Cortex infrastructure as canonical agent-bom inventory. It supports discover-only local output by default, with optional scanning when the operator asks for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The workflow inventories Snowflake assets and may expose environment metadata if run against the wrong account or role.\n\nMitigation: Run it only for operator-approved Snowflake accounts, warehouses, databases, and read-only roles.\n\nRisk: Snowflake passwords, tokens, private keys, or passphrases could be exposed if pasted into chat or logs.\n\nMitigation: Use the operator's existing SSO, OAuth, or key-pair environment and do not request or display credential material.\n\nRisk: Inventory output could be written somewhere unintended or shared before review.\n\nMitigation: Verify the operator-selected output path, keep output local by default, and inspect or redact inventory before sharing.\n\n## Reference(s):\n\n- [agent-bom GitHub repository](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with shell commands and JSON file outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces operator-selected local inventory JSON and, when requested, local agent-bom scan findings JSON.]\n\n## Skill Version(s):\n\n0.105.0 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.104.0: 3 files, 3516 bytes\n\nFiles: skill-card.md (2509b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.104.0:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.104.0\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.104.0:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.104.0\",\n  \"publishedAt\": 1788987436636\n}\n\nFile v0.104.0:skill-card.md\n\n## Description:\n\nDiscovers Snowflake Cortex, Snowpark, notebooks, Streamlit, MCP, and AI-observability assets from the operator's environment, emits canonical agent-bom inventory JSON, and supports an optional local scan without giving agent-bom long-lived Snowflake credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nApache-2.0\n\n## Use Case:\n\nDevelopers, platform engineers, and security reviewers use this skill to inventory Snowflake AI and workload assets into schema-valid agent-bom JSON. It is intended for operator-approved, read-only discovery and optional local findings generation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill uses the operator's existing Snowflake authentication context for read-only inventory.\n\nMitigation: Use only operator-approved Snowflake accounts, warehouses, databases, and read-only roles, and prefer SSO, OAuth, or key-pair authentication over passwords.\n\nRisk: Redacted inventory and query-history metadata can still reveal sensitive business context.\n\nMitigation: Review generated inventory and findings files before sharing them outside the operator environment.\n\nRisk: Credential material could be exposed if pasted into chat or written into generated outputs.\n\nMitigation: Do not request or display Snowflake passwords, private key contents, passphrases, or OAuth tokens; keep credentials in the operator environment.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom source](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, code, JSON]\n\n**Output Format:** [Markdown guidance with bash command examples and JSON inventory or findings file outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes inventory JSON to an operator-selected path and can optionally write local agent-bom findings JSON when the operator asks for a scan.]\n\n## Skill Version(s):\n\n0.104.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.103.2: 3 files, 3477 bytes\n\nFiles: skill-card.md (2463b), SKILL.md (4508b), _meta.json (149b)\n\nFile v0.103.2:SKILL.md\n\n---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.103.2\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invocation: restricted\n---\n\n# agent-bom-discover-snowflake\n\nUse this skill to collect Snowflake AI and workload inventory as schema-valid\nagent-bom inventory. Default to discover-only: write JSON to an\noperator-selected path and stop.\n\n## Guardrails\n\n- Use only operator-approved Snowflake accounts, warehouses, databases, and\n  read-only roles.\n- Prefer SSO, OAuth, or key-pair auth. Do not request or display\n  `SNOWFLAKE_PASSWORD`, private key contents, passphrases, or OAuth tokens.\n- Do not modify Snowflake resources. This workflow is discovery-only.\n- Write inventory only to a path the operator chose.\n- Treat AI-generated prose as non-authoritative; schema-validated inventory JSON\n  is the evidence.\n\n## Workflow\n\n```bash\npython examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json\n```\n\nScan only when the operator asks for findings:\n\n```bash\nagent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json\n```\n\n## Evidence Contract\n\nThe emitted inventory carries `discovery_provenance.source_type:\nskill_invoked_pull`, `observed_via: skill_invoked_pull, snowflake_sdk`,\nsanitized `metadata.permissions_used`, and redacted credential material. If\nschema validation fails, stop and fix the inventory instead of scanning a\nbest-effort summary.\n\nFile v0.103.2:_meta.json\n\n{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.103.2\",\n  \"publishedAt\": 1788333921031\n}\n\nFile v0.103.2:skill-card.md\n\n## Description:\n\nDiscover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Snowflake credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to inventory Snowflake AI, Cortex, Snowpark, notebook, Streamlit, MCP, and observability assets into canonical agent-bom JSON. It supports discovery-only workflows first, with optional local agent-bom scanning when the operator asks for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Snowflake inventory may cover sensitive AI, Cortex, query history, and observability assets.\n\nMitigation: Install only for intended Snowflake inventory work and review the generated inventory JSON before sharing, scanning, or pushing it elsewhere.\n\nRisk: Using broad Snowflake permissions could expose more account metadata than needed for discovery.\n\nMitigation: Use operator-approved Snowflake accounts, warehouses, databases, and read-only roles.\n\nRisk: Long-lived credentials or secret values could be exposed if pasted into chat or persisted in outputs.\n\nMitigation: Prefer SSO, OAuth, or key-pair authentication, keep credentials in the operator environment, and do not request or display passwords, private keys, passphrases, or OAuth tokens.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom PyPI package](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, Guidance, JSON files]\n\n**Output Format:** [Markdown guidance with bash commands and JSON file outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes an operator-selected inventory JSON file and can optionally write JSON scan findings.]\n\n## Skill Version(s):\n\n0.103.2 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: agent-bom discover snowflake Owner: msaad00 Summary: Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving agent-bom long-lived Snowflake credentials. Use when a user asks to inventory Snowflake AI or Cortex infrastructure as canonical inventory. Tags: latest:0.108.3 Version","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json"},{"language":"bash","snippet":"python examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json"},{"language":"bash","snippet":"python examples/operator_pull/snowflake_inventory_adapter.py \\\n  --account \"$SNOWFLAKE_ACCOUNT\" \\\n  --user \"$SNOWFLAKE_USER\" \\\n  --authenticator snowflake_jwt \\\n  --source snowflake-skill-invoked \\\n  --discovery-method skill_invoked_pull \\\n  --output snowflake-inventory.json"},{"language":"bash","snippet":"agent-bom scan --inventory snowflake-inventory.json --format json --output agent-bom-snowflake-findings.json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-bom-discover-snowflake\ndescription: >-\n  Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and\n  AI-observability assets from the operator's environment, emit canonical\n  agent-bom inventory JSON, and scan it without giving agent-bom long-lived\n  Snowflake credentials. Use when a user asks to inventory Snowflake AI or\n  Cortex infrastructure as canonical inventory.\nversion: 0.108.3\nlicense: Apache-2.0\ncompatibility: >-\n  Requires Python 3.11+, agent-bom installed with the snowflake extra, and\n  operator-controlled Snowflake read-only credentials. Prefer SSO, OAuth, or\n  key-pair auth over passwords.\nmetadata:\n  author: msaad00\n  homepage: https://github.com/msaad00/agent-bom\n  source: https://github.com/msaad00/agent-bom\n  pypi: https://pypi.org/project/agent-bom/\n  openclaw:\n    requires:\n      bins:\n        - python\n      env: []\n      credentials: snowflake-read-only\n    credential_policy: \"Use the operator's existing Snowflake SSO, OAuth, or key-pair auth context. Prefer SNOWFLAKE_PRIVATE_KEY_PATH or SNOWFLAKE_AUTHENTICATOR over SNOWFLAKE_PASSWORD. Do not ask users to paste passwords, private keys, or OAuth tokens into chat.\"\n    optional_env:\n      - SNOWFLAKE_ACCOUNT\n      - SNOWFLAKE_USER\n      - SNOWFLAKE_AUTHENTICATOR\n      - SNOWFLAKE_PRIVATE_KEY_PATH\n      - SNOWFLAKE_PRIVATE_KEY_PASSPHRASE\n      - SNOWFLAKE_TOKEN\n      - SNOWFLAKE_WAREHOUSE\n      - SNOWFLAKE_DATABASE\n      - SNOWFLAKE_SCHEMA\n      - SNOWFLAKE_ROLE\n    optional_bins:\n      - snow\n      - snowsql\n    emoji: \"search\"\n    homepage: https://github.com/msaad00/agent-bom\n    source: https://github.com/msaad00/agent-bom\n    license: Apache-2.0\n    os:\n      - darwin\n      - linux\n      - windows\n    credential_handling: \"Credentials stay in the operator environment. The skill invokes Snowflake discovery locally and writes canonical inventory JSON with source_type=skill_invoked_pull. agent-bom receives sanitized inventory only when the operator explicitly scans or pushes that inventory.\"\n    data_flow: \"Operator Snowflake account -> read-only Snowflake queries/API calls -> canonical inventory JSON -> optional local agent-bom inventory scan. No agent-bom-hosted service is required. Credential-like values are redacted before persistence/export.\"\n    file_reads:\n      - \"~/.snowflake/connections.toml\"\n      - \"~/.snowflake/config.toml\"\n      - \"operator-selected private key path when SNOWFLAKE_PRIVATE_KEY_PATH is set\"\n    file_writes:\n      - \"operator-selected inventory JSON output path\"\n    network_endpoints:\n      - url: \"https://{account}.snowflakecomputing.com\"\n        purpose: \"Snowflake inventory, Cortex, query history, and AI observability discovery\"\n        auth: true\n      - url: \"https://*.snowflakecomputing.com\"\n        purpose: \"Snowflake regional and organization account endpoints selected by the operator\"\n        auth: true\n    telemetry: false\n    persistence: false\n    privilege_escalation: false\n    always: false\n    autonomous_invoc"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7612j2dqa4vhvcpaygt6mcv981pft8\",\n  \"slug\": \"agent-bom-discover-snowflake\",\n  \"version\": \"0.108.3\",\n  \"publishedAt\": 1791497943698\n}"},{"path":"skill-card.md","content":"## Description:\n\nDiscovers Snowflake AI and workload assets and produces canonical agent-bom inventory for optional scanning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[msaad00](https://clawhub.ai/user/msaad00)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and Snowflake operators use this skill to inventory Cortex, Snowpark, notebooks, Streamlit, MCP, and AI-observability assets with their own read-only credentials, then optionally scan the resulting inventory for findings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Discovery uses the operator's Snowflake authentication context.\n\nMitigation: Use only approved accounts and a least-privilege, read-only Snowflake role; do not share credentials in chat.\n\nRisk: Generated inventory may reveal internal Snowflake assets even when credential-like values are redacted.\n\nMitigation: Choose the inventory output path and review the JSON before sharing or scanning it.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/msaad00/skills/agent-bom-discover-snowflake)\n- [agent-bom project homepage](https://github.com/msaad00/agent-bom)\n- [agent-bom on PyPI](https://pypi.org/project/agent-bom/)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Files]\n\n**Output Format:** [Markdown instructions and canonical JSON inventory; optional JSON scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Inventory is written to an operator-selected path; scanning is optional and requires an explicit request.]\n\n## Skill Version(s):\n\n0.108.3 (source: frontmatter and server release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1067,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:33:51.188Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:37:47.347Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}