motherduckdb/agent-skills386 installs
motherduck-security-governance
Assess MotherDuck security, permissions, isolation, residency, and compliance requirements against documented controls.
How do I install this agent skill?
npx skills add https://github.com/motherduckdb/agent-skills --skill motherduck-security-governanceIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides security guidelines and audit queries for MotherDuck environments. It helps users verify access controls and isolation boundaries without introducing security risks.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Security and Governance
Source Of Truth
- Prefer current MotherDuck public trust, security, pricing, and product documentation.
- If the MotherDuck MCP
ask_docs_questionfeature is available, use it first. - Use current SSO and data-recovery docs when the requirement involves identity-provider login, restore windows, named snapshots, or
UNDROP DATABASE. - Verify claims against live public materials before making compliance or commercial assertions.
Default Posture
- Prefer service accounts for production systems, not personal tokens.
- Keep credentials in backend-controlled secrets, not browsers or hardcoded notebooks.
- Prefer structural isolation over query-time tenant filtering for serious B2B or CFA workloads.
- Treat region and residency as first-class architectural constraints that require current public confirmation.
- Be explicit about whether the boundary is a share, a Dive, a database, or a full application.
- Separate platform permissions (roles), data grants (who can attach a share), and include patterns (which tables/views that share exposes).
- Separate documented product guarantees from architectural recommendations and assumptions in the final answer.
Workflow
- Identify where credentials live and who administers them.
- Define the actual isolation boundary: account, database, schema, or query filter.
- Determine which preset/custom roles users hold, who can read, write, share, or administer the data, and which grants actually provide access.
- Check whether residency, compliance, or contractual guarantees are part of the requirement.
- Use only publicly documented security anchors unless the user has current commercial documentation in hand.
References
Read only the reference sections needed for the current task.
- Read
references/SECURITY_GOVERNANCE_PLAYBOOK.mdfor public security anchors, service-account posture, residency framing, sharing boundaries, and what not to overstate
Related Skills
Load related skills only for missing capabilities; reuse established context.
motherduck-connectfor secure token handling and endpoint selectionmotherduck-explorewhen governance depends on what data is actually present and how it is partitionedmotherduck-share-datawhen the design includes governed data distribution
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/motherduckdb/agent-skills/motherduck-security-governance">View motherduck-security-governance on skillZs</a>