cso

Audit software project infrastructure, dependencies, and supply-chain risks across OWASP and STRIDE.

Updated Mar 25, 2026
One-click install
npx skills add https://github.com/Chang-Shih-Yung/auto-learning --skill cso-chang-shih-yung
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Chang-Shih-Yung/auto-learning/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/Chang-Shih-Yung/auto-learning --skill cso-chang-shih-yung

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Keeping modern software secure means auditing infrastructure, dependencies, and CI/CD processes, which is complex and error-prone. This skill packages an infrastructure-first security audit that reveals secrets archaeology, dependency-risk, pipeline weaknesses, and LLM/AI security gaps.

Core Features & Use Cases

  • Infrastructure-first security audits across CI/CD pipelines, dependencies, and LLM security.
  • Active verification of OWASP Top 10, STRIDE threat modeling, and skill supply chain scanning.
  • Two modes: daily baseline audit and comprehensive monthly deep scan.
  • Actionable remediation recommendations with concrete steps.

Quick Start

Ask me to run a daily infrastructure-first security audit with /cso to surface immediate risks.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my CI/CD pipeline for supply-chain security risks?

An infrastructure-first security audit evaluates CI/CD pipelines, dependencies, and LLM integrations to identify supply-chain threats. It applies threat modeling across OWASP, STRIDE, and LLM security concerns to surface risks and return concrete remediation recommendations.

What is the best way to run a security audit for LLM and AI integrations?

The best way to audit LLM security is running a multi-phase audit across infrastructure, code, and skills scopes. This evaluates LLM/AI security gaps alongside active OWASP Top 10 and STRIDE threat modeling to produce actionable remediation steps.

Can I use threat modeling to verify my project's dependency risks and secrets?

Yes, you can verify dependency risks and secrets through an infrastructure-first security audit. It performs secrets archaeology and dependency-risk scanning, applying STRIDE threat modeling to identify and remediate pipeline weaknesses in your software projects.

Does infrastructure-first security auditing work for both daily and comprehensive scans?

Infrastructure-first security auditing supports both daily baseline audits and comprehensive monthly deep scans. It runs a multi-phase audit across infra, code, and skills scopes to continuously verify security posture and generate remediation recommendations.

When do I need a comprehensive security posture audit across OWASP Top 10 and STRIDE?

You need a comprehensive security posture audit when verifying ongoing risks across OWASP Top 10 and STRIDE frameworks. A multi-phase audit evaluates infrastructure, dependencies, and supply-chain threats to deliver concrete remediation recommendations for your software projects.