What problem does it solve?
In real-world software, the biggest risks sit in dependencies, secrets, and CI/CD pipelines. Teams often assume code is safe, leaving open attack surfaces that attackers exploit through leaked credentials, insecure configurations, and insecure supply chains. This skill provides a security posture report framework to expose those gaps and guide remediation for stakeholders.
Core Features & Use Cases
- End-to-end security posture audits spanning code, dependencies, CI/CD, and infrastructure.
- Secrets archaeology to uncover leaked keys, tokens, and sensitive config in repos and builds.
- Dependency supply chain risk assessment with concrete remediation steps and governance signals.
- Threat modeling guidance using OWASP Top 10, STRIDE, and active verification to validate controls.
- Produce repeatable audit cycles (daily or comprehensive monthly) with traceable evidence and reporting.
Quick Start
Run the /cso command to start a daily security audit and generate a Security Posture Report for your team.