motherduck-security-governance

Installation
SKILL.md

Security and Governance

Source Of Truth

  • Prefer current MotherDuck public trust, security, pricing, and product documentation.
  • If the MotherDuck MCP ask_docs_question feature is available, use it first.
  • Use current SSO and data-recovery docs when the requirement involves identity-provider login, restore windows, named snapshots, or UNDROP DATABASE.
  • Verify claims against live public materials before making compliance or commercial assertions.

Default Posture

  • Prefer service accounts for production systems, not personal tokens.
  • Keep credentials in backend-controlled secrets, not browsers or hardcoded notebooks.
  • Prefer structural isolation over query-time tenant filtering for serious B2B or CFA workloads.
  • Treat region and residency as first-class architectural constraints that require current public confirmation.
  • Be explicit about whether the boundary is a share, a Dive, a database, or a full application.
  • Separate platform permissions (roles), data grants (who can attach a share), and include patterns (which tables/views that share exposes).
  • Separate documented product guarantees from architectural recommendations and assumptions in the final answer.
Installs
363
GitHub Stars
61
First Seen
Apr 15, 2026
motherduck-security-governance — motherduckdb/agent-skills