cso

Audit software infrastructure for secrets, dependencies, CI/CD, and LLM security.

Updated Jun 4, 2026
One-click install
npx skills add https://github.com/Manzueti/cyberdart --skill cso-manzueti
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Manzueti/cyberdart/tree/main/cso
Command: npx skills add https://github.com/Manzueti/cyberdart --skill cso-manzueti

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Read, Grep, Glob, Write, Agent, WebSearch, AskUserQuestion, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive security audit, identifying vulnerabilities and weaknesses in software infrastructure.

Core Features & Use Cases

  • Infrastructure-First Security Audit: Performs a thorough audit of software infrastructure, including secrets archaeology, dependency supply chain, CI/CD pipeline security, and LLM/AI security.
  • Daily and Comprehensive Scans: Offers two modes of scanning: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar).
  • Trend Tracking: Tracks trends across audit runs for continuous improvement.
  • Use Case: Ideal for security audits, threat modeling, pentest reviews, OWASP reviews, and CSO reviews.

Quick Start

Run the cso skill to initiate a security audit of your infrastructure.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a comprehensive infrastructure security audit for secrets and CI/CD pipeline vulnerabilities?▼

An infrastructure security audit evaluates secrets, dependency supply chains, CI/CD pipelines, and LLM/AI security. It identifies vulnerabilities and weaknesses across your software infrastructure using daily and comprehensive scanning modes.

What is secrets archaeology in the context of a CI/CD pipeline security audit?▼

Secrets archaeology is a security audit phase that uncovers hidden or leaked credentials within your software infrastructure. It evaluates your codebase to identify exposed secrets before they can be exploited.

How do I set up daily vulnerability scanning with trend tracking for my software infrastructure?▼

Daily vulnerability scanning uses a zero-noise mode with an 8/10 confidence gate to surface only high-priority issues. It tracks trends across audit runs to help you monitor continuous security improvements over time.

Does this security audit cover OWASP reviews and LLM/AI security vulnerabilities?▼

Yes, the security audit covers OWASP reviews and includes specific LLM/AI security vulnerability scanning. It is designed for threat modeling and pentest reviews to comprehensively evaluate your infrastructure.

What is the difference between daily and comprehensive vulnerability scanning modes?▼

Daily scanning operates with a zero-noise 8/10 confidence gate for high-priority alerts, while comprehensive scanning performs a monthly deep scan with a 2/10 confidence bar to uncover broader infrastructure weaknesses.

Related Skills