detect-snowflake-session-policy-bypass

Installation
SKILL.md

detect-snowflake-session-policy-bypass

Attack pattern

Snowflake session policies (CREATE SESSION POLICY, ALTER SESSION POLICY) control how long a session can stay idle (SESSION_IDLE_TIMEOUT_MINS) and how long the web UI session can stay idle (SESSION_UI_IDLE_TIMEOUT_MINS) before the user is forced to re-authenticate.

A compromised credential or insider trying to extend their useful session window will raise those thresholds — often to the maximum 240 minutes — so they don't have to re-enter MFA. On the wire this shows up as an ALTER_SESSION_POLICY event with a new SESSION_IDLE_TIMEOUT_MINS / SESSION_UI_IDLE_TIMEOUT_MINS value that exceeds the operator's documented baseline.

This skill keeps the logic narrow to that pattern. It does not flag every session-policy modification, and it does not guess at every other Snowflake policy.

Installs
1
GitHub Stars
3
First Seen
Jun 22, 2026
detect-snowflake-session-policy-bypass — msaad00/cloud-ai-security-skills