What problem does it solve?
The cso Skill solves the problem of comprehensive security audits, focusing on infrastructure, secrets archaeology, dependency supply chain, and more, with an infrastructure-first approach.
Core Features & Use Cases
- Security Audit: Performs a daily audit (8/10 confidence gate) and a monthly deep scan (2/10 bar).
- Secrets Archaeology: Detects leaked credentials in git history and tracked configuration files.
- Dependency Supply Chain: Checks for supply chain risks and known CVEs in direct dependencies.
- CI/CD Pipeline Security: Analyzes GitHub Actions, GitLab CI, and CircleCI workflows for security risks.
- Infrastructure Shadow Surface: Finds shadow infrastructure with excessive access, including Dockerfiles and Terraform configurations.
- Webhook & Integration Audit: Identifies inbound endpoints that accept anything and checks for TLS verification and OAuth scopes.
- LLM & AI Security: Checks for AI/LLM-specific vulnerabilities like prompt injection and unsanitized LLM output.
Quick Start
Run the cso skill with the command: /cso