Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
motherduckdb avatar

Motherduck Security Governance

  • 257 installs
  • 53 repo stars
  • Updated July 31, 2026
  • motherduckdb/agent-skills

Apply MotherDuck security governance—access controls, sharing policies, audit expectations, and secrets handling—before production rollout.

About

Motherduck-security-governance helps agents implement MotherDuck security and governance—role-based access, sharing rules, audit expectations, and secret handling—so analytics platforms meet production compliance before customer data ships.

  • Access control patterns
  • Sharing policy design
  • Audit trail expectations
  • Secrets hygiene
  • Production governance checklist

Motherduck Security Governance by the numbers

  • 257 all-time installs (skills.sh)
  • +16 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #674 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 4, 2026 (Skillselion catalog sync)
npx skills add https://github.com/motherduckdb/agent-skills --skill motherduck-security-governance

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs257
repo stars53
Last updatedJuly 31, 2026
Repositorymotherduckdb/agent-skills

What it does

Apply MotherDuck security governance—access controls, sharing policies, audit expectations, and secrets handling—before production rollout.

Files

SKILL.mdMarkdownGitHub ↗

Security and Governance

Use this skill when the user is evaluating whether MotherDuck can meet their security, governance, and deployment requirements. This is a workflow skill focused on control boundaries and safe patterns.

Source Of Truth

  • Prefer current MotherDuck public trust, security, pricing, and product documentation.
  • If the MotherDuck MCP ask_docs_question feature is available, use it first.
  • Use current SSO and data-recovery docs when the requirement involves identity-provider login, restore windows, named snapshots, or UNDROP DATABASE.
  • Verify claims against live public materials before making compliance or commercial assertions.

Default Posture

  • Prefer service accounts for production systems, not personal tokens.
  • Keep credentials in backend-controlled secrets, not browsers or hardcoded notebooks.
  • Prefer structural isolation over query-time tenant filtering for serious B2B or CFA workloads.
  • Treat region and residency as first-class architectural constraints that require current public confirmation.
  • Be explicit about whether the boundary is a share, a Dive, a database, or a full application.
  • Separate documented product guarantees from architectural recommendations and assumptions in the final answer.

Workflow

1. Identify where credentials live and who administers them. 2. Define the actual isolation boundary: account, database, schema, or query filter. 3. Determine who can read, write, share, or administer the data. 4. Check whether residency, compliance, or contractual guarantees are part of the requirement. 5. Use only publicly documented security anchors unless the user has current commercial documentation in hand.

Open Next

  • Read references/SECURITY_GOVERNANCE_PLAYBOOK.md for public security anchors, service-account posture, residency framing, sharing boundaries, and what not to overstate

Related Skills

  • motherduck-connect for secure token handling and endpoint selection
  • motherduck-explore when governance depends on what data is actually present and how it is partitioned
  • motherduck-share-data when the design includes governed data distribution

Related skills

Securitycomplianceauditsecrets

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.