What problem does it solve?
The cso skill performs infrastructure-first security audits to find leaked secrets, CI/CD and workflow misconfigurations, dependency supply-chain risks, exposed infrastructure, and skill supply-chain issues so teams get an actionable Security Posture Report rather than a noisy checklist.
Core Features & Use Cases
- Phased, prioritized analysis: Runs a mental-model stack detection phase then targeted phases 0-14 covering attack surface mapping, secrets archaeology, dependency scanning, CI/CD review, infra shadow surface, webhook and integration audits, and active verification.
- Modes and scopes: Supports daily zero-noise scans, comprehensive deep scans, scoped audits (infra, code, skills, supply-chain, OWASP), and branch-diff limited scans for PRs.
- Concrete outputs: Produces severity-rated findings, reproducible evidence, remediation steps, and telemetry; ideal for security reviews, pre-release audits, and incident triage.
Quick Start
Run /cso in your Claude session to perform a daily infrastructure-first security audit and receive a Security Posture Report with findings and remediation steps.