cso

Audit software projects for security risks across dependencies, CI/CD, and infrastructure.

Updated Mar 27, 2026
One-click install
npx skills add https://github.com/AlejandroFigini/artist-portfolio --skill cso-alejandrofigini
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/AlejandroFigini/artist-portfolio/tree/main/.agent/skills/cso
Command: npx skills add https://github.com/AlejandroFigini/artist-portfolio --skill cso-alejandrofigini

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill centralizes and automates security auditing for software projects, surfacing weaknesses across code, dependencies, CI/CD, infrastructure, and data flows to help teams locate and remediate risk.

Core Features & Use Cases

  • Phase-based security audits covering secrets archaeology, dependency supply chain, CI/CD pipeline security, infrastructure hardening, LLM/AI risk, Skill supply chain, OWASP Top 10, STRIDE modeling, and data classification.
  • Model-aware, infrastructure-first evaluation with plan-mode safety and guided remediation workflows.
  • Use cases include continuous security monitoring, monthly deep-dive reviews, and rapid triage of high-severity findings to stakeholders.

Quick Start

Instruct Claude to run a full CSO audit on your repository to generate a prioritized risk report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an automated security audit on my codebase?

A security audit analyzes your project's posture by scanning secrets, dependencies, CI/CD pipelines, and infrastructure to surface weaknesses and generate a structured remediation plan with risk severities.

What is the best way to apply OWASP and STRIDE threat modeling during a security review?

OWASP and STRIDE threat modeling is applied through phased security reviews that evaluate attack vectors and data flows, producing structured findings with categorized risk severities and guided remediation steps.

Can I scan large repositories for hardcoded secrets and dependency vulnerabilities?

Yes, you can scan large repositories for hardcoded secrets and dependency vulnerabilities. The audit performs secrets archaeology and supply chain analysis across everyday codebases and large repositories.

Does this security audit support continuous monitoring or is it only for deep-dive reviews?

This security audit supports continuous security monitoring for ongoing risk triage and monthly deep-dive reviews, providing structured risk severity reporting and remediation workflows for stakeholders.

How do I evaluate LLM and AI risks within my software infrastructure?

Evaluating LLM and AI risks is handled through infrastructure-first, model-aware audit phases that assess LLM/AI risks and Skill supply chain vulnerabilities, ensuring plan-mode safety during security assessments.