cso

Scan secrets, supply chains, CI/CD pipelines, and LLM/AI security.

1|Updated Mar 31, 2026
One-click install
npx skills add https://github.com/LaPaGaYo/nexus --skill cso-lapagayo
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/LaPaGaYo/nexus/tree/main/skills/support/cso
Command: npx skills add https://github.com/LaPaGaYo/nexus --skill cso-lapagayo

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides an infrastructure-first security auditing workflow that systematically scans for secrets, supply chain risks, CI/CD vulnerabilities, and adversarial AI threats across skill and host surfaces.

Core Features & Use Cases

  • Secrets archaeology and dependency-supply-chain checks across pipelines and skill surfaces.
  • OSINT-like threat modeling, OWASP Top 10 alignment, and governance checks integrated into lifecycle reviews.
  • Guided remediation workflows with deterministic steps and integration with nexus.skill.yaml manifests.

Quick Start

Invoke a comprehensive security audit on your Nexus-enabled environment and follow the prompts to start the dual-audit workflow.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits for infrastructure and CI/CD pipelines?▼

Automate infrastructure security audits by scanning secrets, dependency supply chains, and CI/CD pipelines across Nexus-hosted hosts and skill surfaces. This workflow systematically detects vulnerabilities and provides actionable remediation during lifecycle reviews.

What is threat modeling for LLM and AI security in skill supply chains?▼

Threat modeling for LLM and AI security involves scanning skill supply chains for adversarial AI threats and OSINT-like risks aligned with OWASP Top 10. It systematically identifies potential attack vectors across skill and host surfaces during governance checks.

Can I use nexus.skill.yaml manifests for governance checks during security audits?▼

Yes, you can use nexus.skill.yaml manifests for governance checks during security audits. The auditing workflow integrates with these manifests to apply deterministic audit steps via scripts across your Nexus-enabled environment.

Does infrastructure security auditing work with YAML frontmatter-driven configuration?▼

Yes, infrastructure security auditing works with YAML frontmatter-driven configuration requiring a mandatory name and description. It uses this configuration to apply deterministic audit steps across Nexus-hosted hosts and skill surfaces.

What is the best way to scan for secrets and dependency supply chain risks across pipelines?▼

The best way to scan for secrets and dependency supply chain risks is using an infrastructure-first security auditing workflow. It performs secrets archaeology and dependency-supply-chain checks across pipelines and skill surfaces with guided remediation.