What problem does it solve?
Security teams need a repeatable, automated CSO-grade audit to identify gaps across infrastructure, CI/CD pipelines, dependency supply chains, and AI model usage. This skill provides an architecture-first approach to secrets archaeology, dependency supply chain checks, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus active verification. Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs.
Core Features & Use Cases
- Architecture-first security assessment covering infrastructure, CI/CD, and AI model governance.
- Secrets archaeology, dependency-supply-chain checks, and active verification aligned with OWASP and STRIDE threat modeling.
- Generate a Security Posture Report with prioritized remediation plans and executive summaries.
Quick Start
Run the CSO audit to begin an automated security posture assessment across your infrastructure and code.