cso

Audit codebase security across infrastructure, dependencies, CI/CD, and AI tooling.

5|1|Updated Apr 5, 2026
One-click install
npx skills add https://github.com/forbotsake/forbotsake --skill cso-forbotsake
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/forbotsake/forbotsake/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/forbotsake/forbotsake --skill cso-forbotsake

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audit to surface weaknesses across your stack, from secrets in the codebase to insecure CI/CD pipelines and risky AI tooling.

Core Features & Use Cases

  • Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10 and STRIDE threat modeling.
  • Active verification and risk reduction with multi-stage scans and proof-of-compliance checks.
  • Trend tracking across audit runs to show improvement over time.

Quick Start

Run a daily audit with /cso to start the security posture review.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my codebase for security vulnerabilities across infrastructure and CI/CD?

To audit your codebase for security vulnerabilities, this Skill scans infrastructure, dependencies, CI/CD pipelines, and AI tooling to surface risks. It performs secrets archaeology and supply-chain scanning to generate a Security Posture Report with remediation steps.

What is STRIDE threat modeling and OWASP Top 10 scanning for application security?

STRIDE threat modeling and OWASP Top 10 scanning are security frameworks applied here to identify architectural and implementation risks. This Skill uses them alongside infrastructure checks to comprehensively evaluate your security posture and highlight areas needing risk reduction.

How do I check for exposed secrets and risky dependencies in my software supply chain?

Checking for exposed secrets and risky dependencies involves scanning the codebase and OSS supply chain. This Skill performs secrets archaeology and dependency supply chain analysis to actively verify risks and track security trends across audit runs.

Can I run a daily lightweight security check for LLM and AI tooling risks?

Yes, you can run a daily lightweight security check for LLM and AI tooling risks. The Skill supports daily lightweight checks or monthly deep scans to monitor pipelines, secrets, and AI security, producing a Security Posture Report.

Does this security audit require any external tools or dependencies to run?

No external dependencies are required to run this security audit. The Skill implements a multi-phase workflow using built-in tools like Bash, Read, Grep, and WebSearch to actively verify risks and produce remediation steps without external setup.

What is the best way to track security posture improvement over time?

The best way to track security posture improvement is through trend tracking across audit runs. This Skill records results from daily checks and monthly deep scans, allowing you to monitor risk reduction and verify compliance over time.