cso

Audit security posture across infrastructure, code, and supply chains.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/filipnyquist/caidos --skill cso-filipnyquist
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/filipnyquist/caidos/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/filipnyquist/caidos --skill cso-filipnyquist

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode analyzes and documents security posture across the software stack, revealing gaps in infrastructure, code, and supply chains so teams can act decisively.

Core Features & Use Cases

  • Infrastructure-first security audits: secrets archaeology, dependency supply chain checks, and CI/CD pipeline security.
  • Threat modeling & verification: OWASP Top 10, STRIDE, and active verification with daily (8/10) and comprehensive (2/10) gates.
  • Trend tracking: monitor audit results across runs to measure improvements and detect regressions.

Quick Start

Run a daily CSO audit against your project to surface high-confidence findings and track long-term security improvements.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a threat modeling audit using OWASP Top 10 and STRIDE guidelines?

Threat modeling audits using OWASP Top 10 and STRIDE guidelines analyze your software stack to document security posture, revealing infrastructure and code gaps. The process enforces dual-mode verification gates to ensure continuous compliance and active risk assessment.

What is the best way to audit dependency supply chain and CI/CD pipeline security?

Auditing dependency supply chains and CI/CD pipeline security involves scanning infrastructure to uncover hidden secrets and validate pipeline configurations. This approach enforces daily high-confidence checks and comprehensive monthly reviews to track security posture trends.

Does this security audit tool support tracking infrastructure regressions over time?

Yes, security audit tracking monitors audit results across multiple runs to measure improvements and detect regressions. By enforcing daily 8/10 and monthly 2/10 verification gates, it maintains consistent infrastructure and code security trend analysis.

Can I perform secrets archaeology and infrastructure security checks at scale?

Secrets archaeology and infrastructure security checks scale across the software stack by analyzing and documenting security posture comprehensively. This reveals gaps in infrastructure, code, and supply chains so teams can act decisively on high-confidence findings.

What are the limitations of daily versus comprehensive security verification gates?

Daily security verification gates surface 8/10 high-confidence findings for immediate action, while comprehensive monthly gates run 2/10 deep checks. This dual-mode approach balances rapid threat detection with thorough long-term security posture validation.

How do I start a CSO-grade security audit for my software team?

Start a CSO-grade security audit by running a daily scan against your project to surface high-confidence findings. This enforces dual-mode gates aligned with OWASP Top 10 and STRIDE, tracking long-term security improvements across infrastructure and code.