cso

Identify and catalog security weaknesses across infrastructure, dependencies, and CI/CD pipelines.

Updated Feb 5, 2026
One-click install
npx skills add https://github.com/CaltexBevo/ihe-pulse --skill cso-caltexbevo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/CaltexBevo/ihe-pulse/tree/main/.claude/skills/gstack.bak/cso
Command: npx skills add https://github.com/CaltexBevo/ihe-pulse --skill cso-caltexbevo

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps security teams build a repeatable, infrastructure-first audit program that surfaces secrets, supply chain risks, CI/CD weaknesses, and LLM/AI security gaps before they become incidents.

Core Features & Use Cases

  • Secrets archaeology: discover exposed credentials and weak secrets across code, config, and pipelines.
  • Dependency supply chain scanning: identify vulnerable or outdated components and risky transitive dependencies.
  • CI/CD pipeline security: assess build and deploy tooling for misconfigurations and secret leaks.
  • LLM/AI security: evaluate prompt safety, data handling, and model interactions to prevent leaks or prompt-injection.
  • Active verification: produce evidence-backed remediation steps and verifications across audits.
  • Threat modeling & OWASP alignment: apply STRIDE and OWASP Top 10 checks to standardize risk rankings.

Quick Start

Run a daily CSO audit to surface security posture findings and generate an actionable Security Posture Report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my infrastructure for exposed secrets and CI/CD misconfigurations?

To audit infrastructure for exposed secrets and CI/CD misconfigurations, run a security posture check that scans code, configurations, and build pipelines to surface weak credentials and deploy tooling risks, then generates actionable remediation steps.

What is the best way to apply OWASP Top 10 and STRIDE threat modeling to daily security checks?

The best way to apply OWASP Top 10 and STRIDE threat modeling is running automated daily posture checks that standardize risk rankings across infrastructure, dependencies, and pipelines, yielding verifiable, evidence-backed security findings.

Can I scan my software supply chain for vulnerable or outdated dependencies?

Yes, you can scan your software supply chain to identify vulnerable, outdated components and risky transitive dependencies, which allows your security team to catalog supply chain risks before they escalate into incidents.

How do I evaluate LLM security and prevent prompt-injection in my AI applications?

To evaluate LLM security and prevent prompt-injection, you assess prompt safety, data handling, and model interactions within your AI applications, producing actionable findings that prevent data leaks and malicious model manipulations.

Does this security audit approach provide verifiable evidence for compliance reporting?

Yes, this security audit approach provides verifiable evidence for compliance by generating evidence-backed remediation steps and verification checks across daily posture audits and monthly deep reviews of infrastructure and dependencies.

When should I run a deep security audit versus a daily posture check?

You should run daily security posture checks for routine identification of infrastructure weaknesses and exposed secrets, while scheduling monthly deep audits for comprehensive OWASP Top 10, threat modeling, and LLM security evaluations.