detect-snowflake-unauthorized-grant

Installation
SKILL.md

detect-snowflake-unauthorized-grant

Attack pattern

Snowflake's role hierarchy puts a small set of system roles (ACCOUNTADMIN, SECURITYADMIN, ORGADMIN) at the top of every account. Any user holding one of these roles can read every table, alter every warehouse, and grant the role onward. An attacker who reaches a role with OWNERSHIP on ACCOUNTADMIN (or MANAGE GRANTS) can grant a privileged role to an attacker-controlled identity outside the documented break-glass process, persisting access until a human notices.

On the wire the pattern is:

  • GRANT ROLE ACCOUNTADMIN TO USER <name>
  • GRANT ROLE SECURITYADMIN TO USER <name>
  • GRANT ROLE ORGADMIN TO USER <name>
Installs
1
GitHub Stars
3
First Seen
Jun 24, 2026
detect-snowflake-unauthorized-grant — msaad00/cloud-ai-security-skills