cso

Audit infrastructure, dependencies, and code for security posture gaps.

Updated Mar 31, 2026
One-click install
npx skills add https://github.com/hetsheth-droid/toolbox-template --skill cso-hetsheth-droid
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/hetsheth-droid/toolbox-template/tree/main/incubating/gstack/cso
Command: npx skills add https://github.com/hetsheth-droid/toolbox-template --skill cso-hetsheth-droid

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security auditing to uncover secrets, supply-chain, and pipeline risks before they bite.

Core Features & Use Cases

  • Comprehensive CSO-style audits across infrastructure, dependencies, CI/CD, and AI systems.
  • OWASP Top 10, STRIDE threat modeling, secrets archaeology, and supply chain risk scoring.
  • Actionable remediation guidance with traceable evidence and risk-driven prioritization.

Quick Start

Run the /cso command to perform a daily security audit and review the resulting Security Posture Report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security posture audit across my infrastructure and code?▼

Security posture audits identify and report gaps across infrastructure, dependencies, and code by performing CSO-grade assessments. They score findings and produce actionable remediation guidance with verifiable evidence for daily risk verification.

What is STRIDE threat modeling and when do I need it for CI/CD security?▼

STRIDE threat modeling is a structured technique applied during security audits to systematically identify and categorize threats across CI/CD pipelines and AI systems. You need it for monthly deep-dive risk assessments and comprehensive vulnerability discovery.

How do I check my supply chain and dependencies for security risks?▼

You can check supply chain risks by executing an infrastructure-first security audit that uncovers secrets, supply-chain, and pipeline vulnerabilities. The audit scores dependencies and provides traceable evidence with risk-driven prioritization for remediation.

Does this security audit cover the OWASP Top 10 and LLM security vulnerabilities?▼

Yes, the security audit covers the OWASP Top 10 and LLM security by orchestrating daily risk verification and monthly deep-dive assessments. It applies CSO-grade auditing to identify and report posture gaps across AI systems and infrastructure.

What is the best way to find exposed secrets in my codebase and pipelines?▼

The best way to find exposed secrets is through secrets archaeology, a process included in comprehensive security posture audits. It uncovers hidden credentials across infrastructure and CI/CD pipelines before they cause security breaches.

Can I use these audits for both daily risk verification and monthly assessments?▼

Yes, you can use these audits for both daily risk verification and monthly deep-dive assessments. The audit orchestrates multiple phases to identify security posture gaps and generate actionable remediation guidance suited for both operational frequencies.