SkillAtlasSkill 详情

connection-auth-rules

Monte Carlo's official toolkit for AI coding agents.

审核状态:已审核Quality 80Security 80

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年9月13日

MC Agent Toolkit

Monte Carlo's official toolkit for AI coding agents. Brings data observability — lineage, monitoring, validation, alerting, and metadata ingestion — directly into your development workflow. The toolkit bundles multiple skills into a single plugin that works across supported editors.

Using Claude.ai (web or desktop) instead of a coding agent? Monte Carlo is a verified connector in the Claude directory — install it directly.

Features

The toolkit bundles the following capabilities as a single mc-agent-toolkit plugin. Each feature is a skill that can also be used standalone.

Skills are grouped by the job they help you do. Orchestrated workflows sequence individual skills into guided multi-step flows; atomic skills can be invoked directly by name. Both are loaded the same way.

Trust — pre-query and pre-build checks

SkillDescriptionDetails
Asset HealthSingle-table health report: freshness, active alerts, monitor coverage, importance, and upstream issues. Run before building on a table.README

Incident Response — triage, investigate, fix

SkillDescriptionDetails
Incident Response (workflow)Orchestrates full incident lifecycle — triage → root cause → remediation → prevent recurrence.SKILL
Automated TriageScores and prioritizes active alerts; runs deep troubleshooting on high-signal ones.SKILL
Analyze Root CauseInvestigates incidents via lineage tracing, ETL checks, query analysis, and data profiling.README
RemediationProposes and executes fixes for data-quality alerts; assesses blast radius before acting, or escalates with full context.README
Troubleshoot Agent TracesInvestigates AI-agent alerts (evaluation, metric, trajectory, validation) and agent traces — kicks off the trace troubleshooting agent and guides a backend-aware manual investigation.README

Monitoring — coverage gaps, monitor creation, noise reduction

SkillDescriptionDetails
Proactive Monitoring (workflow)Sequences coverage analysis → gap identification → monitor creation into a guided flow.SKILL
Monitoring AdvisorIdentifies coverage gaps and creates monitors for warehouse tables or AI agents — validates tables and fields against your live workspace, emits monitors-as-code YAML.README
Manage MaCCreate, edit, validate, and import Monitors-as-Code YAML files — authors new monitors from scratch, modifies existing files, validates against the published JSON Schema, and exports live monitors to YAML.SKILL
Tune MonitorRecommends sensitivity, segment, and schedule changes to reduce alert noise on an existing metric monitor.SKILL

Prevent — catch issues before they ship

SkillDescriptionDetails
PreventEdit-lifecycle safety net for dbt/SQL: surfaces blast radius and monitor gaps before edits, generates monitors-as-code for new logic. Auto-activates via hooks.README
Generate Validation NotebookGenerates targeted SQL validation queries for a dbt PR or local repo change.README

Optimize — cost and performance

SkillDescriptionDetails
Storage Cost AnalysisIdentifies storage waste (unread, zombie, dead-end tables); uses lineage to verify cleanup is safe and estimates savings.README
Performance DiagnosisDiagnoses slow pipelines and expensive queries across Airflow, dbt, Databricks, and other platforms.README

Setup — ingestion and connections

SkillDescriptionDetails
Push IngestionGenerates collection scripts to push metadata, lineage, or query logs to Monte Carlo from any data source.README
Connection Auth RulesBuilds Connection Auth Rules JSON for a Monte Carlo connection type using live connector schemas.SKILL
Instrument AgentInstruments a Python AI agent for Monte Carlo Agent Observability — detects AI libraries, installs the Monte Carlo OpenTelemetry SDK, sets up tracing, and verifies traces in Monte Carlo. Asks before editing.SKILL

Installing the plugin (recommended)

Monte Carlo recommends installing the mc-agent-toolkit plugin. The plugin bundles all skills together with hooks, the Monte Carlo MCP server, and agent-specific capabilities — no separate MCP configuration or authentication setup needed. See the plugins page for the full list of supported coding agents.

Claude Code

  1. Add the marketplace:
    /plugin marketplace add monte-carlo-data/mc-agent-toolkit
    
  2. Install the plugin:
    /plugin install mc-agent-toolkit@mc-marketplace
    
  3. Updates — claude plugin update pulls in the latest skill and hook changes.

See the Claude Code plugin README for detailed setup and usage.

For other coding agents (Cursor, Copilot CLI, OpenCode, Codex, Cortex Code), see the plugins page for installation guides.

Using skills directly (advanced)

Skills can also be used standalone without the plugin. This is for users who want to install individual skills via registries or use them with agents not listed above.

Prerequisites

  • A Monte Carlo account with Editor role or above

  • Monte Carlo MCP server — configure with:

    claude mcp add --transport http monte-carlo-mcp https://mcp.getmontecarlo.com/mcp
    

    Then authenticate: run /mcp in your editor, select monte-carlo-mcp, and complete the OAuth flow.

    See official docs for other MCP clients and advanced options.

    Legacy: header-based auth (for MCP clients without HTTP transport)

    If your MCP client doesn't support HTTP transport, use .mcp.json.example with npx mcp-remote and header-based authentication. See the MCP server docs for details.

Installation

npx skills add monte-carlo-data/mc-agent-toolkit --skill prevent

Or copy directly:

cp -r skills/prevent ~/.claude/skills/prevent

See the skills directory for the full list and individual READMEs.

Telemetry

All six editor plugins send an anonymous install beacon — a Toolkit Installed event carrying an opaque per-install UUID, a per-session UUID, the toolkit version, and the editor name — once per machine per toolkit version (first install and after each version change), so we can count installations and version adoption. The Claude Code and Cortex Code plugins additionally send anonymous skill-usage telemetry (which skills are invoked, how often). As of v1.13.3, the same install_id and toolkit version also ride as HTTP headers on authenticated MCP requests to the Monte Carlo MCP server, so the otherwise-anonymous install can be correlated with the account's MCP tool usage server-side. No prompts, skill arguments, or code are ever sent, and telemetry is fail-open and non-blocking. To disable all of it, set MC_AGENT_TOOLKIT_TELEMETRY_DISABLED=1. See each plugin's README (e.g. Claude Code, Cortex Code) for details.

Contributing

See CONTRIBUTING.md for guidelines on adding skills, creating plugins, and submitting pull requests. It also covers plugin architecture and releasing new versions.

License

This project is licensed under the Apache-2.0 license — see LICENSE for details.

Security

See SECURITY.md for reporting vulnerabilities.

Agent / MCP / Skill 创作

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:1 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/monte-carlo-data/mc-agent-toolkit.git
  3. 将 "skills/connection-auth-rules" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/monte-carlo-data/mc-agent-toolkit.git
  3. 将 "skills/connection-auth-rules" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/monte-carlo-data/mc-agent-toolkit.git
  3. 将 "skills/connection-auth-rules" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/monte-carlo-data/mc-agent-toolkit.git
  3. 将 "skills/connection-auth-rules" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/monte-carlo-data/mc-agent-toolkit.git
  3. 将 "skills/connection-auth-rules" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: connection-auth-rules
description: "Build a Connection Auth Rules for a Monte Carlo connection type. Fetches live connector schemas and transform steps from the apollo-agent repo."
bucket: Setup
version: 1.0.0

Connection Auth Rules Builder

Use this skill when the user wants to build a Connection Auth Rules (stored as ctp_config) for a Monte Carlo connection. The config is stored on the Connection object in the monolith and tells the Apollo agent how to transform flat credentials into the driver-specific connect_args format.

When to activate this skill

Activate when the user:

  • Asks to create, build, or generate a Connection Auth Rules
  • Asks what fields are needed for a connection type's Connection Auth Rules
  • Wants to customize credential transformation for a connection
  • Asks about MapperConfig, TransformStep, or CtpConfig
  • Says things like "help me write Connection Auth Rules for X", "what's the connection auth rules format for X"

When NOT to activate this skill

Do not activate when the user is:

  • Creating monitors (use the monitor-creation skill)
  • Investigating data incidents (use the analyze-root-cause skill)
  • Setting up a connection in the UI (this skill builds the JSON config, not UI flows)

Step 1 — List available connection types

Locate the companion script with Bash:

find -L ~/.claude . -name fetch_schema.py -path "*/connection-auth-rules/*" 2>/dev/null | head -1

Then run it:

python3 <script_path> --list

The script outputs JSON. Parse result.connectors — each entry has a name field. Present the names to the user and ask which connection type they want to build a config for.

If the script fails: Show the error output and offer to retry. Do not proceed until you have the connector list.


Step 2 — Fetch the connector schema

Once the user selects a connection type, run the script with that connector name:

python3 <script_path> --connector <name>

The script outputs JSON. Parse result.schema:

  • output_keys — the driver-level connect_args keys the mapper must produce (from the connector's TypedDict)
  • default_field_map — the existing default mapping (credential field → Jinja2 template)
  • default_steps — any default transform steps already configured

Present a summary to the user:

  • The output keys
  • The default mapper field_map entries
  • Any existing steps with their types

Step 3 — Optionally fetch available transform steps

If the connector's default config (from Step 2) already includes steps, or if the user indicates they need custom transform steps, run:

python3 <script_path> --connector <name> --transforms

Parse result.transforms — each entry has:

  • name — the step type string used in "type"
  • step_input — fields the step reads from the pipeline state
  • step_output — derived fields the step writes, referenceable as {{ derived.<key> }} in the mapper
  • step_field_map — typical mapper entry to wire the step's output into connect_args

Present the available steps with their full contracts (input, output, and field_map hint).

If the script fails: Tell the user and offer to retry. You can continue without step data — just describe steps as unknown and ask the user to specify them manually.


Step 4 — Build the mapper

Walk the user through each output key in the TypedDict:

  1. Show the default template from the connector's MapperConfig (if one exists).
  2. Ask if they want to keep the default or customize it.
  3. For custom values, help the user write a Jinja2 template expression.

Jinja2 template help

The template context has two namespaces:

  • raw — the flat credential dict as received. Use {{ raw.field_name }} to reference a credential field directly. Example: {{ raw.client_id }}
  • derived — fields added by transform steps. Use {{ derived.field_name }} to reference a step's output. Example: {{ derived.private_key_pem }}

Common patterns:

  • Simple field reference: "{{ raw.username }}"
  • Conditional/default: "{{ raw.port | default('1433') }}"
  • Concatenation: "{{ raw.host }}:{{ raw.port }}"

When the user doesn't know their credential field names, remind them these come from the Data Collector's credential dict — the keys are whatever the DC sends for that connection type.


Step 5 — Configure transform steps (optional)

If the connector needs steps (e.g. decoding a PEM certificate, constructing a derived field), help the user configure each step. A step dict has these fields:

FieldRequiredDescription
typeyesStep type name (e.g. "load_private_key")
inputyesDict of template strings the step reads (e.g. {"pem": "{{ raw.private_key_pem }}"})
outputyesDict mapping the step's logical output names to derived key names (e.g. {"private_key": "private_key_der"})
whennoJinja2 boolean expression — step only runs if this evaluates to true (e.g. "raw.ssl_ca_pem is defined")
field_mapnoMapper entries contributed only when this step runs — useful for conditional fields

Walk the user through type, input, and output for each step. Ask about when if the step should only run under certain credential conditions (e.g. when an optional SSL cert is present).

Steps run in order before the mapper. The mapper can reference step outputs via {{ derived.<key> }}.


Step 6 — Output the final config

Produce the complete Connection Auth Rules as a Python dict (ready to serialize to JSON for storage). This is stored as ctp_config on the Connection model:

{
    "steps": [
        # each step as a dict, e.g.:
        {
            "type": "load_private_key",
            "input": {
                "pem": "{{ raw.private_key_pem }}"
            },
            "output": {
                "private_key": "private_key_der"
            }
            # optional: "when": "raw.private_key_pem is defined"
        }
    ],
    "mapper": {
        "field_map": {
            "output_key": "{{ raw.credential_field }}",
            # step output referenced as: "private_key": "{{ derived.private_key_der }}"
            # ...
        }
    }
}

Also show the equivalent JSON, since this is what gets stored in the monolith's Connection.ctp_config field and entered in the "Connection auth rules" field in the UI.

Remind the user that validation happens server-side via validateConnectionCtpConfig — they should test the config through that mutation (or the Validate button in the UI) after saving it.


Notes

  • No in-skill validation. The skill helps construct the config but does not execute or validate it. The user validates via the monolith's validateConnectionCtpConfig GraphQL mutation or the Validate button in the "Connection auth rules" UI section.
  • is not None pattern. An empty field_map ({}) is valid — do not treat it as missing. The monolith checks ctp_config is not None, not truthiness.
  • Steps are optional. Most simple connectors use steps: []. Only add steps when the user needs credential transformation (e.g. PEM decoding, composite field construction).
  • Fetch failures are recoverable. If the GitHub API fetch fails, tell the user exactly what failed and offer to retry. Do not silently fall back to guessed schemas.
  • Naming: The user-facing name for this feature is "Connection auth rules". The underlying field and backend model remain ctp_config / CtpConfig.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!