Skip to content
Back to skills

Cocobrew

ASecurity

Run the read-only CocoObserver skill observation loop for CocoBrew improvement and simplification signals.

  • 724 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
ai-agentsgo

Security analysis

A100/100

Pro scans all 10 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add Snowflake-Labs/cocoplus --skill cocobrew --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cocobrew?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cocobrew
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/snowflake-labs-cocobrew-0c332599/badge)](https://www.skillsdirectory.com/skills/snowflake-labs-cocobrew-0c332599)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "observer"
description: "Run the read-only CocoObserver skill observation loop for CocoBrew improvement and simplification signals."
version: "2.0.0"
author: "CocoPlus"
tags:
  - cocoplus
  - cocobrew
  - observer
---

Your objective is to observe CocoPlus skills without modifying them.

## Behavior

CocoObserver is eyes-only. It reads skill files, hooks, docs, and validation output to identify:

- improvement opportunities,
- simplification opportunities,
- cross-cutting principles that apply to many skills,
- open-source/internal boundary risks.

It never edits files. CocoBrew performs changes only after the operator approves a proposed target.

## Detection Signals

- **Skill discovery:** when three or more session signals match a skill category, append a discovery record instead of surfacing immediate advice. CocoPilot may later choose one discovery to present.
- **Convergence detection:** when the same approach has been retried repeatedly with diminishing returns, emit a `diverge` recommendation and suggest a Snowflake frame shift: FinOps, SRE/on-call, data governance, or data consumer.
- **Script-first gaps:** if a deterministic sub-task is handled through prompt prose, recommend moving it to `scripts/`.
- **Reference loading gaps:** if deep domain knowledge is embedded directly in SKILL.md, recommend moving it to `references/` and loading on demand.
- **Marketplace readiness:** for distributable CocoPods, check explicit permissions, evals, failure behavior, install-time execution, and network justification.

## Outputs

- `.cocoplus/skills/observations.jsonl`: append-only observations with file, signal type, evidence, and recommendation.
- `.cocoplus/skills/cross-cutting-principles.md`: proposed checklist entries that future skill creation or modification must consult.
- `.cocoplus/session/discoveries.jsonl`: skill-match and convergence signals consumed by CocoPilot.

## Exit Criteria

- [ ] Every observation cites exact files read.
- [ ] Simplification signals are treated as first-class findings.
- [ ] Deterministic work is recommended as script work, not token generation.
- [ ] Convergence findings recommend isolated divergence rather than another same-frame retry.
- [ ] Public skills do not receive private implementation details.

## Anti-Rationalization

| Shortcut / Temptation | Why It Fails |
|-----------------------|--------------|
| Treat the skill as complete because the file exists | Skill contracts must describe observable behavior and verification, not just command names. |
| Skip artifact and safety checks for a small command | Small commands still mutate state or guide execution; preserve the same gates. |

Files in this skill

  • build.skill.md4.1 KB
  • distribute.skill.md2.8 KB
  • observer.skill.md2.6 KB
  • plan.skill.md6.9 KB
  • review.skill.md5.3 KB
  • ship.skill.md8.2 KB
  • spec.skill.md10.4 KB
  • test.skill.md3.9 KB
  • worktree-utils.md580 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…