cso

Audit infrastructure security across secrets, dependencies, CI/CD, and LLM integrations.

1|Updated Apr 13, 2026
One-click install
npx skills add https://github.com/a29paul/hexlens --skill cso-a29paul
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/a29paul/hexlens/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/a29paul/hexlens --skill cso-a29paul

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security audits often miss critical infrastructure vulnerabilities like exposed secrets in CI logs, stale API keys, and vulnerable dependencies. This skill provides an infrastructure-first security audit that covers the full attack surface, from secrets archaeology to OWASP Top 10 and STRIDE threat modeling.

Core Features & Use Cases

  • Infrastructure-First Approach: Prioritizes real-world attack vectors like CI/CD secrets, dependency supply chains, and LLM security over code-level checklist scanning.
  • Dual Audit Modes: Daily zero-noise audits with an 8/10 confidence gate, or comprehensive monthly deep scans with a 2/10 bar for thorough coverage.
  • Comprehensive Coverage: Spans secrets archaeology, dependency scanning, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Use Case: A team preparing for a security review can run a daily audit to catch high-confidence issues, or a comprehensive monthly scan to deep-dive into potential vulnerabilities across the entire stack.

Quick Start

Use the cso skill to run a full security audit on your project, covering infrastructure, dependencies, and application code.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit covering CI/CD pipelines and dependency supply chains?

To run an infrastructure security audit, use this skill to scan for vulnerabilities across CI/CD pipelines, dependency supply chains, secrets, and application code. It prioritizes real-world attack vectors over basic code-level checklist scanning.

What is STRIDE threat modeling and OWASP Top 10 coverage in a security review?

STRIDE threat modeling and OWASP Top 10 coverage are security frameworks applied during the audit to identify vulnerabilities across application code and infrastructure. This skill actively integrates both methodologies to ensure comprehensive threat assessment.

Can I configure confidence gates to reduce false positives during dependency scanning?

Yes, you can configure confidence gates for dependency scanning. The skill supports dual audit modes: a daily zero-noise audit with an 8/10 confidence gate, or a comprehensive monthly deep scan with a 2/10 bar for thorough coverage.

Does this security audit check for exposed secrets in CI logs and stale API keys?

Yes, this security audit checks for exposed secrets in CI logs and stale API keys. It performs secrets archaeology to uncover hidden credentials across your infrastructure, ensuring comprehensive secrets detection.

What is the best way to prepare for penetration testing on a software project?

The best way to prepare for penetration testing is to run a comprehensive monthly deep scan with a low confidence gate. This infrastructure-first audit identifies potential vulnerabilities across your entire stack before active verification.

How does LLM integration security factor into an application code audit?

LLM integration security is assessed as part of the infrastructure-first audit approach. The skill scans LLM and AI integrations for vulnerabilities alongside application code, CI/CD pipelines, and dependency supply chains to cover the full attack surface.