cso

Audit infrastructure security for secrets, supply chain, CI/CD, and LLM risks.

1|Updated Apr 15, 2026
One-click install
npx skills add https://github.com/tyhuffman7/gstack-hermes --skill cso-tyhuffman7
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/tyhuffman7/gstack-hermes/tree/main/gstack-cso
Command: npx skills add https://github.com/tyhuffman7/gstack-hermes --skill cso-tyhuffman7

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits that uncover secrets, supply-chain risk, CI/CD vulnerabilities, and LLM/AI security gaps across your stack. It provides a structured approach to verify controls, model threats, and drive remediation with governance-ready outputs. Two modes exist: daily quick checks and comprehensive monthly deep audits, with trend tracking across runs to demonstrate improvement over time.

Core Features & Use Cases

  • Daily quick checks with an 8/10 confidence gate to surface fresh risks across infrastructure, code, and configurations.
  • Comprehensive monthly deep audits for thorough risk assessment, including dependency supply chain and CI/CD pipeline security.
  • Threat modeling, OWASP coverage, and active verification with remediation guidance and governance reporting.
  • Use cases include pre-release security posture validation, incident postmortems, and ongoing risk-trend analysis for policy compliance.

Quick Start

Run the cso skill to perform a daily security audit and generate a posture report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan infrastructure for exposed secrets and CI/CD vulnerabilities?▼

Run an infrastructure-first security audit to scan code, configurations, and CI/CD pipelines for exposed secrets and supply chain risks. The daily quick check mode surfaces fresh risks fast using an 8/10 confidence gate.

What is the best way to track security posture trends across monthly audits?▼

Track security posture trends by running comprehensive monthly deep audits that assess dependency supply chains and LLM/AI gaps. The process verifies controls and generates governance-ready reports demonstrating improvement over time.

How do I perform threat modeling and check OWASP coverage for a pre-release validation?▼

Perform threat modeling and verify OWASP coverage during a pre-release security posture validation. The audit applies active verification to identify risks and provides remediation guidance for closing gaps.

Can I use automated auditing for incident postmortems and compliance risk analysis?▼

Yes, use automated auditing for incident postmortems and ongoing risk-trend analysis for policy compliance. It evaluates vendor ecosystems and LLM security gaps, producing governance-ready outputs for postmortem reviews.

Does the security audit cover LLM and AI security gaps in my stack?▼

Yes, the security audit covers LLM and AI security gaps across your stack. It scans infrastructure, code, and vendor ecosystems to identify supply-chain risks and model threats specific to AI implementations.

When should I run a daily quick check instead of a comprehensive deep audit?▼

Run a daily quick check to rapidly surface fresh risks across configurations with an 8/10 confidence gate. Run a comprehensive monthly deep audit for thorough risk assessment across dependency supply chains and CI/CD pipelines.