What problem does it solve?
Finds and prioritizes real security weaknesses across code, infrastructure, CI/CD, dependencies, and AI/skill supply chains so teams stop chasing noisy false positives and focus on exploitable issues and actionable remediation.
Core Features & Use Cases
- Architecture-first scanning: Detects stack and framework, then prioritizes checks for secrets, CI leaks, exposed credentials, stale infrastructure, and misconfigured services.
- Dependency and supply-chain analysis: Flags vulnerable or malicious dependencies, supply-chain risks in CI/CD, and dependency provenance issues.
- Agent and LLM risk checks: Inspects skill supply chains, prompt/tool usage, and telemetry patterns for potential prompt injection or data leakage.
- Modes and scope: Supports daily (noisy-minimized) and comprehensive deep scans, infra-only, code-only, skills-only, and diff-based branch scans that limit checks to changed files.
- Output: Produces a Security Posture Report with findings, severity, reproducible evidence, and prioritized remediation steps.
Quick Start
Run /cso to perform a daily infrastructure-first security audit of the repository and generate a Security Posture Report with prioritized findings and remediation steps.