cso

Audit infrastructure-first security across secrets, supply chains, and CI/CD pipelines.

Updated Apr 12, 2026
One-click install
npx skills add https://github.com/adryanmoldokkr32-pixel/gstack --skill cso-adryanmoldokkr32-pixel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/adryanmoldokkr32-pixel/gstack/tree/main/cso
Command: npx skills add https://github.com/adryanmoldokkr32-pixel/gstack --skill cso-adryanmoldokkr32-pixel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

CSO mode enables infrastructure-first security audits across secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning, with proactive verification and trend tracking across audit runs.

Core Features & Use Cases

  • Infrastructure-first security audits across secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning.
  • Coverage of OWASP Top 10, STRIDE threat modeling, and active verification to identify and remediate risk.
  • Two modes: daily zero-noise scans (8/10 confidence) and comprehensive monthly deep scans (2/10 bar), with support for threat modeling, pentest reviews, and CSO reviews.

Quick Start

Run the cso skill on your project to start a daily audit, or pass --comprehensive for a monthly deep scan.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit for OWASP and STRIDE threat modeling?

You can perform an infrastructure security audit by running multi-phase checks that evaluate OWASP Top 10 and STRIDE threat modeling to identify and remediate risks across code, infrastructure, and vendor integrations.

What is the difference between daily and comprehensive security posture scans?

Daily security scans operate at an 8/10 confidence threshold for zero-noise results, while comprehensive monthly deep scans lower the bar to 2/10 for exhaustive threat modeling and pentest reviews.

Can I use this for secrets archaeology and supply chain security?

Yes, the security audit covers secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning to improve your overall security posture.

How do I track security audit trends across multiple runs?

You can track security audit trends across multiple runs using the built-in reporting mechanism, which records active verification results and posture improvements over time.

Do I need any dependencies to perform a CSO review and pentest assessment?

No dependencies are required to perform a CSO review and pentest assessment, as the audit uses built-in tools like Bash, Read, Grep, and WebSearch for active verification.