What problem does it solve?
Security audits often miss critical infrastructure vulnerabilities like exposed secrets in CI logs, stale API keys, and vulnerable dependencies. This skill provides an infrastructure-first security audit that covers the full attack surface, from secrets archaeology to OWASP Top 10 and STRIDE threat modeling.
Core Features & Use Cases
- Infrastructure-First Approach: Prioritizes real-world attack vectors like CI/CD secrets, dependency supply chains, and LLM security over code-level checklist scanning.
- Dual Audit Modes: Daily zero-noise audits with an 8/10 confidence gate, or comprehensive monthly deep scans with a 2/10 bar for thorough coverage.
- Comprehensive Coverage: Spans secrets archaeology, dependency scanning, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
- Use Case: A team preparing for a security review can run a daily audit to catch high-confidence issues, or a comprehensive monthly scan to deep-dive into potential vulnerabilities across the entire stack.
Quick Start
Use the cso skill to run a full security audit on your project, covering infrastructure, dependencies, and application code.