Skip to content
Back to skills

Cocopilot

ASecurity

Activate CocoPilot mode for the current CocoPlus session.

  • 724 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 5, 2026
ai-agentsgosqlperformance

Works with

  • mcp

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add Snowflake-Labs/cocoplus --skill cocopilot --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cocopilot?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cocopilot
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/snowflake-labs-cocopilot-cocoplus/badge)](https://www.skillsdirectory.com/skills/snowflake-labs-cocopilot-cocoplus)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "pilot-on"
description: "Activate CocoPilot mode for the current CocoPlus session."
version: "2.0.2"
author: "CocoPlus"
tags:
  - cocoplus
  - cocopilot
  - v2
---

Your objective is to activate CocoPilot for the current session.

## Behavior

1. Verify `.cocoplus/` exists.
2. Create `.cocoplus/modes/cocopilot.on`.
3. Create or update `.cocoplus/lifecycle/pilot-session.json`:
   - `active: true`
   - `activated_at`
   - `session_id`
   - empty arrays for `suggestions`, `routed_inputs`, and `silent_actions` when absent
4. Check the first-run configuration gate:
   - If `.cocoplus/lifecycle/cocoplus-init.json` is absent or has `confirmed: false`, surface the five key settings before any dispatch: default warehouse, cost ceiling per run, production schema prefix, development schema prefix, and notification target.
   - Confirmed changes belong in `cocoplus.toml`; the confirmation receipt belongs in `.cocoplus/lifecycle/cocoplus-init.json`.
   - The gate is reset by `$cocoplus reset-init`.
5. Read `[cocopilot] premortem_enabled` and `premortem_warn_on_absent`.
   - For any stage with `premortem: true`, `allow_irreversible_actions: true`, or `require_outcome_verification: true`, prepare a pre-dispatch pre-mortem before routing work.
   - Record three likely failure scenarios, prevention status, and any operator acknowledgment in `PROGRESS.md` before dispatch.
6. Read `.cocoplus/wisdom/SCHEMA.md` when present.
   - If `[wisdom].stage_mappings_enabled` is not false and a `## Stage Mappings` table matches the stage role, preload only the mapped positive wisdom topics.
   - Always load `.cocoplus/wisdom/do-not-use.md` when it exists.
   - For Snowflake task patterns, prefer the static Cortex MCP routing table over ad hoc capability guessing:
     - schema validation: `OBJECT_DEPENDENCIES`
     - SQL performance: `QUERY_HISTORY`
     - data quality: `COLUMN_USAGE_VIEWS`
     - governance review: policy, tag, masking, and role metadata views
7. Before dispatch, if `[cocopod].instruction_rubric_enforcement_enabled = true`, ensure `lifecycle/rubric.json` exists and matches `lifecycle/cocopod-instructions.md`. Queue operation-level checks after tool calls and stage-level checks at CocoFlow completion; never turn evaluator unavailability into a dispatch failure.
8. If `[cocowisdom].autonomous_wisdom_reflection_enabled = true`, preserve the configured turn cadence and route reflection boundaries to the read-only proposer. Do not let CocoPilot apply reflection intents directly.
9. Output exactly:
   `CocoPilot active. I'll take it from here.`

## Permission Boundary

CocoPilot may route, suggest, and perform reversible silent capture. It may not perform irreversible actions, bypass underlying feature approval gates, or override explicit developer instructions.

## Exit Criteria

- [ ] `.cocoplus/modes/cocopilot.on` exists.
- [ ] `.cocoplus/lifecycle/pilot-session.json` has `active: true`.
- [ ] First-run configuration is confirmed in `lifecycle/cocoplus-init.json` before first dispatch.
- [ ] Pre-mortem stages record `premortem_enabled` behavior and acknowledgments before execution.
- [ ] Stage-mapped wisdom loads only the routed positive topics, while `do-not-use.md` remains universal.
- [ ] Enabled instruction rubrics are current before dispatch and enforcement failures remain fail-open.
- [ ] Enabled autonomous reflection routes through proposer/promoter separation.

## Anti-Rationalization

| Shortcut / Temptation | Why It Fails |
|-----------------------|--------------|
| Treat the skill as complete because the file exists | Skill contracts must describe observable behavior and verification, not just command names. |
| Skip artifact and safety checks for a small command | Small commands still mutate state or guide execution; preserve the same gates. |

Files in this skill

  • pilot-off.skill.md1004 B
  • pilot-on.skill.md3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…