cso

Audit infrastructure, CI/CD pipelines, and AI systems for security posture gaps.

Updated Mar 14, 2026
One-click install
npx skills add https://github.com/Bradliebs/VolumeTurtle --skill cso-bradliebs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Bradliebs/VolumeTurtle/tree/main/.gstack/cso
Command: npx skills add https://github.com/Bradliebs/VolumeTurtle --skill cso-bradliebs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides infrastructure-first security auditing to uncover secrets, dependency supply chain weaknesses, CI/CD pipeline risks, LLM/AI safety concerns, and overall threat modeling gaps, enabling teams to see and fix blind spots early.

Core Features & Use Cases

  • Daily zero-noise risk checks with an 8/10 confidence gate and a monthly deep scan with a 2/10 bar.
  • Threat modeling coverage using OWASP Top 10 and STRIDE, plus active verification across the stack.
  • Voice triggers and a defined set of allowed tooling to guide automated audits and issue triage.

Quick Start

Run the CSO audit on your project with /cso or /cso --comprehensive.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit to uncover secrets and CI/CD pipeline risks?

Run an infrastructure security audit by executing /cso for daily zero-noise risk checks or /cso --comprehensive for a monthly deep scan. This surfaces critical vulnerabilities across secrets archaeology, CI/CD pipelines, and dependencies.

What is STRIDE threat modeling and how does it apply to LLM security?

STRIDE threat modeling identifies security posture gaps across AI systems and infrastructure. It pairs with LLM security checks and OWASP Top 10 analysis to actively verify and remediate threat modeling gaps in your stack.

Can I use automated threat modeling for daily risk monitoring on my infrastructure?

Yes, you can use automated threat modeling for daily risk monitoring with an 8/10 confidence gate to minimize noise. A monthly deep scan lowers the bar to 2/10 to uncover broader dependency supply chain weaknesses.

Does this security audit cover dependency supply chain risks and OWASP Top 10 vulnerabilities?

Yes, this security audit covers dependency supply chain risks and OWASP Top 10 vulnerabilities. It performs an infra-first CSO-mode audit to identify and remediate security posture gaps across your infrastructure.

What is the best way to remediate secrets archaeology findings in CI/CD pipelines?

The best way to remediate secrets archaeology findings is guided issue triage using allowed tools like Bash, Grep, and Read. This active verification process surfaces and fixes critical vulnerabilities hidden in CI/CD pipelines.