Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ibm-self-serve-assets/building-blocks --skill watsonxdata-lakehousegit clone --depth 1 https://github.com/ibm-self-serve-assets/building-blocksWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ibm-self-serve-assets/building-blocks/watsonxdata-lakehouse)<a href="https://agentmods.dev/skills/ibm-self-serve-assets/building-blocks/watsonxdata-lakehouse"><img src="https://agentmods.dev/badge/skills/ibm-self-serve-assets/building-blocks/watsonxdata-lakehouse/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ibm-self-serve-assets/building-blocks/watsonxdata-lakehouse"><img src="https://agentmods.dev/badge/skills/ibm-self-serve-assets/building-blocks/watsonxdata-lakehouse.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.01595 |
| Opus 5 | $0.00044 | $0.00797 |
| Sonnet 5 | $0.00018 | $0.00319 |
| Haiku 4.5 | $0.00009 | $0.00160 |
Grade B, and why
watsonxdata-lakehouse scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
resp = requests.post("https://iam.cloud.ibm.com/identity/token", Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
resp = requests.post("https://iam.cloud.ibm.com/identity/token", How it starts
The opening of the file, as written. The whole thing — 175 lines — stays where its author put it; the contents beside it link to each section on GitHub.
IBM watsonx.data Zero-Copy Lakehouse Builder
Purpose
Expert guidance for configuring IBM watsonx.data as a zero-copy lakehouse — registering storage buckets, connecting databases, associating catalogs with Presto engines, and running federated SQL queries — all via the watsonx.data REST API v2.
IBM Cloud Product Coverage
| IBM Cloud Product | Usage |
|---|---|
| IBM watsonx.data | REST API v2: /bucket_registrations, /presto_engines, /catalogs, /database_registrations |
| IBM Cloud IAM | POST /identity/token (apikey grant) — with auto-refresh |
| IBM Cloud Object Storage | Registered as managed bucket in watsonx.data |
| IBM Db2 | Registered as external database connection |
| Apache Iceberg | Table format for open lakehouse storage |
| Apache Spark | Heavy ETL jobs on Iceberg tables |
| Presto | Interactive federated SQL queries |
Objective
Generate production-ready Python 3.12 scripts that:
- Authenticate to IBM Cloud via
IAMTokenManager(5-minute buffer refresh) - Register IBM COS, AWS S3, and other buckets as watsonx.data storage
- Connect Db2, PostgreSQL, MySQL databases to watsonx.data
- Associate catalogs with Presto engines for federated queries
- Create Iceberg schemas and tables
- Follow the existing
watsonxdata_setup.pypatterns exactly
Rules
- Base URL pattern:
https://{region}.lakehouse.cloud.ibm.com/lakehouse/api/v2 - Always build headers with
{"Authorization": "Bearer {token}", "AuthInstanceId": AUTH_INSTANCE_ID, "Content-Type": "application/json"} - The
AuthInstanceIdis the watsonx.data CRN (from config) - Use
wait_with_progress(seconds)for delays between API operations - All resource registrations are synchronous — allow 30–90 second waits for catalog propagation
- Supported regions:
us-south,eu-de,au-syd,jp-tok
Scope
- IBM watsonx.data instance configuration and bucket registration
- IBM COS, AWS S3, Azure ADLS bucket registration
- IBM Db2, PostgreSQL, MySQL database connections
- Presto engine catalog association
- Apache Iceberg schema and table creation via Presto SQL
- Apache Spark job configuration for Iceberg ETL
- Federated query patterns across heterogeneous sources
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 175 lines · 88 tokens per session scan B 9751f3252a8e
watsonxdata-lakehouse is a skill published in the GitHub repository ibm-self-serve-assets/building-blocks (24 stars, last pushed today), licensed Apache-2.0. It adds 88 tokens to every session and 1,595 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it B with 2 findings (sends data to an external url, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
google-cloud-storage-fuse
Mounts Cloud Storage buckets as a POSIX file system with Cloud Storage FUSE (gcsfuse). Use when interacting with gcsfuse: decide whether FUSE, native gs:// reads, or Filestore/Managed Lustre fits a workload, deploy tuned mounts on GKE, Compute Engine, or Cloud Run, enable and size file, stat, and list caches, tune…
cloud-databases-onboarding
Guides users through discovering their database requirements, recommends a Google Cloud database based on a recommendation matrix, and assists in database creation. Use when a user asks 'What database service should I use?', 'Help me pick a database', or when a user wants to create a new database on Google Cloud.…
cloud-sql-basics
This file generates or explains Cloud SQL resources. Use this file when the user asks to create a Cloud SQL instance or database for MySQL, PostgreSQL, or SQL Server. Cloud SQL manages third-party MySQL, PostgreSQL, and SQL Server instances as resources in Cloud SQL. For example, when Cloud SQL creates an open-source…
azure-resource-manager-mysql-dotnet
Azure MySQL Flexible Server SDK for .NET. Database management for MySQL Flexible Server deployments. Use for creating servers, databases, firewall rules, configurations, backups, and high availability. Triggers: "MySQL", "MySqlFlexibleServer", "MySQL Flexible Server", "Azure Database for MySQL", "MySQL database…
azure-mgmt-mongodbatlas-dotnet
Manage MongoDB Atlas Organizations as Azure ARM resources using Azure.ResourceManager.MongoDBAtlas SDK. Use when creating, updating, listing, or deleting MongoDB Atlas organizations through Azure Marketplace integration. This SDK manages the Azure-side organization resource, not Atlas clusters/databases directly.
azure-resource-manager-redis-dotnet
Azure Resource Manager SDK for Redis in .NET. Use for MANAGEMENT PLANE operations: creating/managing Azure Cache for Redis instances, firewall rules, access keys, patch schedules, linked servers (geo-replication), and private endpoints via Azure Resource Manager. NOT for data plane operations (get/set keys, pub/sub) …