cso

Audit infrastructure, dependencies, CI/CD, and LLM security with trend tracking.

37|2|Updated Mar 28, 2026
One-click install
npx skills add https://github.com/DariusCorvus/iqualize --skill cso-dariuscorvus
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/DariusCorvus/iqualize/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/DariusCorvus/iqualize --skill cso-dariuscorvus

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure and operations teams often struggle to assess and improve security posture across complex software systems. This CSO-oriented skill provides an end-to-end security audit workflow covering infrastructure, pipelines, dependencies, and AI/LLM risk to surface vulnerabilities and guide remediation.

Core Features & Use Cases

  • Infrastructure-first security audit coverage: secrets archaeology, dependency supply chain, CI/CD security, and LLM/AI security.
  • OWASP Top 10, STRIDE threat modeling, and active verification with trend tracking across runs.
  • Production-grade remediation governance to close gaps and reduce risk over time.

Quick Start

Run the CSO audit workflow to generate a comprehensive security posture report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a CI/CD pipeline security audit?

A CI/CD pipeline security audit uses automated checks via Bash, Grep, and Read to detect vulnerabilities and gather evidence across your software delivery workflows. It assesses secrets archaeology, dependency supply chains, and pipeline configurations.

What is secrets archaeology in infrastructure security?

Secrets archaeology in infrastructure security is the active scanning of codebases to unearth exposed credentials. It uses tools like Glob and Grep to identify hardcoded secrets and guide remediation planning to close access gaps.

Does this security audit cover LLM and AI vulnerabilities?

Yes, this security audit covers LLM and AI vulnerabilities by evaluating AI-specific attack surfaces alongside traditional infrastructure. It integrates LLM security checks into the overall posture assessment to surface risks in AI-integrated systems.

Can I use STRIDE threat modeling for my dependency supply chain review?

Yes, you can use STRIDE threat modeling to systematically identify threats during a dependency supply chain review. This approach structures active verification and remediation governance to reduce risk across daily and monthly tracking.

What's the best way to track security posture improvements over time?

The best way to track security posture improvements is through active verification with trend tracking across daily and monthly scans. This generates comprehensive posture reports to monitor remediation governance and risk reduction over time.