cso

Audit infrastructure, dependencies, CI/CD, and AI risk with OWASP Top 10 and STRIDE.

9|3|Updated Jan 29, 2022
One-click install
npx skills add https://github.com/I194/PMTools_2.0 --skill cso-i194
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/I194/PMTools_2.0/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/I194/PMTools_2.0 --skill cso-i194

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning.
  • OWASP Top 10, STRIDE threat modeling, and active verification across audits.
  • Two modes: daily zero-noise (8/10 confidence) and comprehensive monthly scans with trend tracking.

Quick Start

Invoke the /cso audit to start a daily zero-noise security review.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit that covers infrastructure, dependencies, and CI/CD pipelines?▼

An infrastructure-first security audit assesses secrets, dependency supply chains, CI/CD pipelines, and LLM/AI risks. It applies OWASP Top 10, STRIDE threat modeling, and active verification to catch threats across your software project.

What is the difference between daily zero-noise and comprehensive monthly security scans?▼

Daily zero-noise security scans operate at an 8/10 confidence threshold to surface only high-priority threats, while comprehensive monthly scans perform deep audits with trend tracking to monitor security posture improvements over time.

Can I use STRIDE threat modeling and OWASP Top 10 for pentest preparation?▼

Yes, STRIDE threat modeling and OWASP Top 10 checks are integrated into the security audit. They support pentest preparation, security reviews, and supply-chain assessments by actively verifying vulnerabilities.

Does DevSecOps supply-chain scanning cover secrets archaeology and LLM security?▼

Yes, supply-chain scanning includes secrets archaeology to find exposed credentials and LLM/AI security to evaluate model risks. It scans skill supply chains and dependencies to ensure DevSecOps coverage across all project components.

What is the best way to start a zero-noise security review for a software project?▼

The best way to start a zero-noise security review is to invoke the daily audit command within the required gstack CSO workflow. This initiates an infrastructure-first scan targeting high-confidence threats without alert fatigue.