What problem does it solve?
Security audits often miss critical vulnerabilities because teams focus only on application code and ignore infrastructure risks like exposed secrets in CI logs, stale API keys in git history, vulnerable dependencies, and misconfigured CI/CD pipelines. This skill performs comprehensive, infrastructure-first security audits that find what manual reviews miss.
Core Features & Use Cases
- Infrastructure-First Auditing: Scans secrets archaeology, dependency supply chains, CI/CD pipelines, and LLM/AI security before diving into code-level checks.
- Dual-Mode Scanning: Daily zero-noise audits with an 8/10 confidence gate for continuous integration, and comprehensive monthly deep scans with a 2/10 bar for thorough security reviews.
- OWASP & STRIDE Coverage: Includes OWASP Top 10 checks, STRIDE threat modeling, and active verification with confidence scoring and trend tracking across audit runs.
- Use Case: A SaaS company preparing for a compliance audit can run daily scans to catch exposed AWS keys in GitHub Actions logs and vulnerable npm dependencies before they reach production.
Quick Start
Use the cso skill to run a full security audit on this repository and generate a confidence-scored posture report with prioritized remediation steps.