python

A set of guidance for using the Snowflake Python connector, which lets Python programs connect to Snowflake and run queries.

In plain words
What is it for?
Use it to inspect connection and authentication implementations, search for timeout or retry handling, and investigate login methods such as Okta.
Why use it?
It helps developers investigate connection failures, authentication methods, retry behavior, multi-factor authentication, and Python-specific connector code.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/sfc-gh-cconner/support-rules-mcp/python
Clone the repo
git clone --depth 1 https://github.com/sfc-gh-cconner/support-rules-mcp
Per session 1,600 This file is loaded in full into every session.
When invoked 1,600 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01600 $0.01600
Opus 5 $0.00800 $0.00800
Sonnet 5 $0.00320 $0.00320
Haiku 4.5 $0.00160 $0.00160

Measured yesterday against content hash 39d66e95700a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

python scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

rules/connectors/python.mdc · 251 lines

How it starts

The opening of the file, as written. The whole thing — 251 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Snowflake Python Connector Investigation Guide

PURPOSE: Python connector patterns for connecting to Snowflake, executing queries, and handling Python-specific features.

Access Method: GitHub MCP API tools
Repository: snowflakedb/snowflake-connector-python

🔍 Quick Investigation Patterns

Connection Issues

# Search for connection errors
mcp_github_search_code(
    query='"connection failed" OR "connection timeout" repo:snowflakedb/snowflake-connector-python'
)

# Get connection implementation
mcp_github_get_file_contents(
    owner="snowflakedb",
    repo="snowflake-connector-python",
    path="src/snowflake/connector/connection.py"
)

# Search for retry logic
mcp_github_search_code(
    query='retry_pattern OR DEFAULT_SOCKET_CONNECT_TIMEOUT repo:snowflakedb/snowflake-connector-python'
)

Authentication Issues

# Search for auth implementations
mcp_github_search_code(
    query='path:src/snowflake/connector/auth repo:snowflakedb/snowflake-connector-python'
)

# Get specific auth module
mcp_github_get_file_contents(
    owner="snowflakedb",
    repo="snowflake-connector-python",
    path="src/snowflake/connector/auth/okta.py"
)

# Search for MFA handling
mcp_github_search_code(
    query='mfa_token OR duo_push repo:snowflakedb/snowflake-connector-python'
)

OCSP Issues

# Search for OCSP validation
mcp_github_search_code(
    query='path:src/snowflake/connector/ocsp repo:snowflakedb/snowflake-connector-python'
)

# Get OCSP checker
mcp_github_get_file_contents(
    owner="snowflakedb",
    repo="snowflake-connector-python",
    path="src/snowflake/connector/ocsp_snowflake.py"
)

# Search for OCSP cache
mcp_github_search_code(
    query='OCSP_RESPONSE_CACHE repo:snowflakedb/snowflake-connector-python'
)

Session Management

# Search for session handling
mcp_github_search_code(
    query='"Session no longer exists" OR session_token repo:snowflakedb/snowflake-connector-python'
)

# Get session implementation
mcp_github_get_file_contents(
    owner="snowflakedb",
    repo="snowflake-connector-python",
    path="src/snowflake/connector/auth/by_plugin.py"
)

# Search for heartbeat logic
mcp_github_search_code(
    query='heartbeat OR _heartbeat_thread repo:snowflakedb/snowflake-connector-python'
)

Read the full file on GitHub · 251 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 251 lines · 1,600 tokens per session scan A 39d66e95700a

Subscribe to this mod's changes

python is a cursor rule published in the GitHub repository sfc-gh-cconner/support-rules-mcp (0 stars, last pushed 10mo ago), licensed Apache-2.0. It adds 1,600 tokens to every session, about $0.0080 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.