detect-snowflake-network-policy-disable

Installation
SKILL.md

detect-snowflake-network-policy-disable

Attack pattern

Snowflake network policies are IP-allowlist objects bound at the account or user level. Disabling or widening them is a clean way for an attacker to keep a compromised credential reachable from an arbitrary IP:

  • ALTER ACCOUNT SET NETWORK_POLICY = NULL removes the account-wide policy entirely.
  • ALTER NETWORK POLICY <name> SET ALLOWED_IP_LIST = ('0.0.0.0/0') widens the policy to permit every public IP.
  • ALTER NETWORK POLICY <name> UNSET BLOCKED_IP_LIST removes blocks that had previously kept attacker ranges out.

This skill keeps the logic narrow to those three flavors. It does not flag benign policy renames or rotations to a different, still-restrictive allowlist.

Installs
1
GitHub Stars
3
First Seen
Jun 19, 2026
detect-snowflake-network-policy-disable — msaad00/cloud-ai-security-skills