What problem does it solve?
Infrastructure teams often risk security gaps across the build, deployment, and supply chain; this Skill provides a structured audit approach that surfaces secrets, supply chain flaws, and misconfigurations.
Core Features & Use Cases
- Secrets archaeology to locate exposed credentials in repos and configs.
- Dependency supply chain scanning for vulnerable packages and compromised chains.
- CI/CD pipeline security checks to prevent insecure deployments.
- LLM/AI security checks to guard prompts, data handling, and tool usage.
- Skill supply chain scanning to monitor internal tools and third-party components.
- OWASP Top 10 and STRIDE threat modeling with active verification.
- Daily quick checks and comprehensive monthly deep scans to track risk over time.
Quick Start
Activate the cso audit by running /cso for a daily check or /cso --comprehensive for a deep monthly scan.