cso

Audit infrastructure security across secrets, supply chain, CI/CD, and AI systems.

1|Updated Nov 13, 2025
One-click install
npx skills add https://github.com/concept2cure/ClinicalSageAI-2-replit --skill cso-concept2cure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/concept2cure/ClinicalSageAI-2-replit/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/concept2cure/ClinicalSageAI-2-replit --skill cso-concept2cure

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The CSO audit skill provides infrastructure-first security assessment to uncover secrets, verify supply chain integrity, evaluate CI/CD security, and strengthen AI/LLM safety, helping security teams measure posture accurately.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD security, LLM/AI security, and active verification.
  • Two modes: daily lightweight checks and monthly deep scans to track risk over time.
  • Threat modeling and compliance alignment with OWASP Top 10 and STRIDE, with guidance for remediation.

Quick Start

Ask me to run '/cso' for a daily audit or '/cso --comprehensive' for a full monthly scan.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure-first security audit across code, CI/CD, and dependencies?

A supply chain security audit verifies dependency integrity and uncovers hidden secrets in code configurations. It performs secrets archaeology and dependency risk analysis to trace vulnerabilities and provide actionable remediation guidance for your software pipeline.

Can I use STRIDE threat modeling and OWASP Top 10 for active security verification?

Yes, STRIDE threat modeling and OWASP Top 10 compliance alignment are applied during active security verification. The assessment maps threats to traceable remediation guidance, actively verifying risks across infrastructure, deployment pipelines, and AI/LLM security layers.

What is the best way to assess AI and LLM security risks in deployment pipelines?

Assessing AI and LLM security risks involves evaluating model safety and pipeline configurations during end-to-end audits. The process identifies vulnerabilities in AI integrations and provides traceable remediation guidance aligned with infrastructure-first risk assessment methodologies.

Does this security audit support both daily lightweight checks and monthly deep scans?

Yes, the security audit supports two modes: daily lightweight checks for rapid posture measurement and monthly deep scans for comprehensive analysis. Both modes track risk trends across runs to ensure continuous security visibility across code, config, and deployment pipelines.

When do I need a comprehensive security audit for secrets archaeology and CI/CD pipelines?

A comprehensive security audit is needed when measuring deep infrastructure risks across secrets archaeology, CI/CD pipelines, and supply chains. It performs active verification and threat modeling to uncover hidden vulnerabilities that daily lightweight checks might miss.