cso

Automate infrastructure-first security audits and risk assessments for cloud, CI/CD, and AI/LLM environments.

4|2|Updated Mar 29, 2026
One-click install
npx skills add https://github.com/florianhorner/mammamiradio --skill cso-florianhorner
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/florianhorner/mammamiradio/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/florianhorner/mammamiradio --skill cso-florianhorner

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits and governance are hard to scale; this Skill provides a structured, repeatable CSO-level assessment workflow that surfaces risks across cloud, CI/CD, and AI integrations.

Core Features & Use Cases

  • Daily zero-noise security checks to verify configurations, surface high-confidence risks with auditable evidence, and guide remediation.
  • Comprehensive monthly scans covering OWASP Top 10, STRIDE threat modeling, LLM/AI security, and supply-chain reviews for governance and compliance.
  • Integrated governance with CI/CD pipelines and AI systems to enforce policies, track remediation, and improve risk posture over time.

Quick Start

Run the daily security audit and schedule the monthly comprehensive review to establish and maintain a strong security baseline.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate an infrastructure security audit for CI/CD pipelines and cloud deployments?

Automate infrastructure security audits by applying structured risk assessment workflows that verify configurations, surface high-confidence risks with auditable evidence, and guide remediation across CI/CD pipelines and cloud deployments.

What is STRIDE threat modeling and how does it fit into a comprehensive security audit?

STRIDE threat modeling is a structured technique for identifying security threats across system interactions. This skill integrates STRIDE methodology into comprehensive monthly scans to evaluate risk posture and enforce governance compliance.

How do I check OWASP Top 10 vulnerabilities and manage supply chain risks in modern development environments?

Check OWASP Top 10 vulnerabilities and manage supply chain risks through comprehensive monthly scans that cover dependency supply chains, secrets archaeology, and governance checks to maintain a strong security baseline.

Can I enforce LLM security policies and AI integration governance checks across my development workflows?

Yes, you can enforce LLM security policies and AI integration governance checks by integrating automated assessment workflows that track remediation, enforce policies, and improve risk posture over time.

Does this security audit approach scale for organizations needing daily verification without alert fatigue?

Yes, this security audit approach scales for organizations by running daily zero-noise security checks that surface only high-confidence risks with auditable evidence, ensuring verification without alert fatigue.

What's the best way to establish a repeatable CSO-level security baseline for cloud and AI integrations?

Establish a repeatable CSO-level security baseline by running daily security audits to verify configurations and scheduling monthly comprehensive reviews covering OWASP, STRIDE, LLM security, and supply-chain governance.