cso

Audit application code, dependencies, CI/CD pipelines, and LLM systems for exploitable vulnerabilities.

Updated May 22, 2026
One-click install
npx skills add https://github.com/shekerkamma/peopletech-marketplace --skill cso-shekerkamma
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/shekerkamma/peopletech-marketplace/tree/main/plugins/gstack/cso
Command: npx skills add https://github.com/shekerkamma/peopletech-marketplace --skill cso-shekerkamma

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most teams only audit their own application code, missing 80% of the real attack surface: exposed secrets in CI logs, stale API keys in git history, unpatched critical dependencies, misconfigured CI/CD pipelines, and LLM-specific risks like prompt injection and RAG poisoning. This skill cuts through security theater to find the actual unlocked doors in your infrastructure and code, no checkbox scanning.

Core Features & Use Cases

  • Dual audit modes: Run low-noise daily scans with an 8/10 confidence gate to catch only high-severity issues, or deep comprehensive monthly scans with a 2/10 bar to surface every potential risk.
  • Full attack surface coverage: Scans for secrets archaeology, dependency supply chain flaws, CI/CD security gaps, OWASP Top 10 vulnerabilities, STRIDE threat model gaps, LLM/AI security risks, and malicious skill supply chain issues.
  • Actionable reporting: Delivers confidence-rated findings with concrete remediation steps, not just vague warnings. Use case: A startup preparing for a SOC 2 audit can run a daily scan to catch exposed AWS keys in git history and unpatched Log4j dependencies before their assessor arrives.

Quick Start

Use the cso skill to run a full daily security audit of your project to identify high-confidence vulnerabilities across your infrastructure, code, and dependencies.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit to find critical vulnerabilities in my code and CI/CD pipelines?▼

Run a security audit using the cso skill to identify exploitable vulnerabilities across application code, dependencies, and CI/CD pipelines. It delivers confidence-rated findings with actionable remediation plans for identified risks.

Can I detect exposed secrets and stale API keys in my git history before a compliance audit?▼

Yes, you can detect exposed secrets and stale API keys in git history by running a security audit. This skill performs secrets archaeology to find exposed credentials across your infrastructure before an assessor arrives.

What is the best way to identify LLM-specific security risks like prompt injection and RAG poisoning?▼

The best way to identify LLM-specific security risks like prompt injection and RAG poisoning is using an infrastructure-first security audit. This skill actively verifies identified AI system risks and provides concrete remediation steps.

Does this vulnerability scanning approach support both daily hygiene checks and deep monthly assessments?▼

Yes, this vulnerability scanning approach supports dual audit modes. You can run low-noise daily scans with an 8/10 confidence gate for high-severity issues, or deep comprehensive monthly scans with a 2/10 bar to surface every potential risk.

How do I perform a supply chain risk assessment for unpatched critical dependencies?▼

Perform a supply chain risk assessment by scanning for dependency supply chain flaws. This skill evaluates your infrastructure to identify unpatched critical dependencies and malicious skill supply chain issues with confidence-rated findings.