cso

Audit security posture across infrastructure, dependencies, and CI/CD pipelines.

1|Updated Mar 28, 2026
One-click install
npx skills add https://github.com/shhubbh/flowstate --skill cso-shhubbh
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/shhubbh/flowstate/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/shhubbh/flowstate --skill cso-shhubbh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams often lack a complete view of risk spanning infrastructure, CI/CD pipelines, dependencies, and AI/LLM interactions. This skill provides an infrastructure-first security audit that finds secrets archaeology, supply-chain risks, threat modeling, and active verification to close gaps before exploitation.

Core Features & Use Cases

  • Infra-first audit across CI/CD, secrets archaeology, supply-chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Daily zero-noise gate with an 8/10 confidence threshold and a comprehensive monthly scan to track trends over time.
  • Active verification and governance by connecting findings to remediation plans and stakeholder communication.

Quick Start

Run a daily infrastructure- and code-focused security audit to surface high-priority risks.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit CI/CD pipelines and infrastructure for security risks?▼

A security posture audit surfaces hidden risks across infrastructure, dependencies, and CI/CD pipelines by enforcing OWASP Top 10, STRIDE threat modeling, and secrets archaeology to drive remediation.

How does STRIDE threat modeling work during a supply-chain scan?▼

STRIDE threat modeling during a supply-chain scan categorizes security risks across infrastructure and dependencies, using active verification to validate vulnerabilities before they can be exploited.

Can I run daily security audits without generating alert fatigue?▼

Daily security audits can run without alert fatigue by enforcing a zero-noise gate with an 8/10 confidence threshold, surfacing only high-priority risks for immediate remediation.

What is the best way to track security posture trends over time?▼

The best way to track security posture trends is by running comprehensive monthly scans alongside daily zero-noise checks, allowing you to monitor infrastructure and dependency risk reduction over time.

Does this security audit include secrets archaeology and active verification?▼

Yes, the security audit includes secrets archaeology to uncover hidden credentials and active verification to confirm vulnerabilities, directly connecting findings to remediation plans and stakeholder communication.

When do I need an infrastructure-first security audit?▼

You need an infrastructure-first security audit when your security teams lack a complete view of risk spanning CI/CD pipelines, dependencies, and infrastructure, requiring active verification to close gaps before exploitation.