cso

Identify secrets, supply-chain risks, and deployment vulnerabilities in AI-driven infrastructure.

Updated Apr 22, 2026
One-click install
npx skills add https://github.com/diiviikk5/rezops --skill cso-diiviikk5
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/diiviikk5/rezops/tree/main/cso
Command: npx skills add https://github.com/diiviikk5/rezops --skill cso-diiviikk5

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill guides security-focused audits of AI-driven infrastructure, helping teams identify secrets, supply-chain risks, and deployment vulnerabilities across CI/CD pipelines.

Core Features & Use Cases

  • Secrets archaeology: discover and inventory leaked or embedded credentials.
  • Dependency supply chain scanning: detect risky components and vulnerable transitive dependencies.
  • CI/CD & pipeline security: assess build and deployment security practices.
  • Threat modeling & OWASP alignment: map threats and align with OWASP Top 10.
  • Active verification & mode switching: run daily zero-noise scans or monthly deep scans with structured reports.

Quick Start

Run a CSO-mode security audit on the current project to begin the assessment.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan CI/CD pipelines for leaked secrets and supply-chain risks?

To scan CI/CD pipelines for leaked secrets and supply-chain risks, run a CSO-mode security audit. It inventories embedded credentials, detects vulnerable transitive dependencies, and assesses deployment security practices across your projects.

What is threat modeling with OWASP alignment for AI-driven infrastructure?

Threat modeling with OWASP alignment maps deployment vulnerabilities and security threats directly to the OWASP Top 10. It helps teams identify risks in AI-driven infrastructure and structure remediation efforts during security audits.

Can I run a security audit on projects of any size without excessive noise?

Yes, you can run security audits on projects of any size without excessive noise by using daily zero-noise scans. This mode enforces high-signal reporting to avoid alert fatigue while continuously monitoring infrastructure.

How do I switch between daily quick scans and monthly deep security audits?

To switch between daily quick scans and monthly deep security audits, toggle the active verification modes in the audit configuration. Monthly deep scans generate structured reports for comprehensive risk assessment and secrets archaeology.

What is the best way to assess dependency supply chain risks in my deployment pipeline?

The best way to assess dependency supply chain risks is performing an infra-first security audit. It actively verifies components to detect risky dependencies and vulnerable transitive packages within your CI/CD deployment pipeline.