cso

Identify security gaps across secrets, dependencies, CI/CD, and AI systems.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/gfires/motion-analysis --skill cso-gfires
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/gfires/motion-analysis/tree/main/cso
Command: npx skills add https://github.com/gfires/motion-analysis --skill cso-gfires

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits that identify secrets exposure, supply-chain risks, CI/CD weaknesses, and AI/LLM security gaps, delivering concrete remediation plans to harden the environment.

Core Features & Use Cases

  • Secrets archaeology: uncover exposed credentials across repositories and CI logs.
  • Dependency supply-chain scanning: verify third-party components and risky transitive dependencies.
  • CI/CD pipeline security: assess pipeline integrity, approvals, and artifact handling.
  • LLM/AI security: detect prompt-injection risks, tool-call permissions, and model exposure.
  • Skill supply chain scanning: evaluate the security of the automation skills ecosystem and dependencies.
  • Active verification: generate a Security Posture Report with severity ratings and prioritized fixes.

Quick Start

Invoke /cso to run a daily security posture audit and generate a Security Posture Report for your organization.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify exposed secrets and supply-chain risks in my CI/CD pipeline?

Conducting a security posture audit scans secrets, dependencies, CI/CD pipelines, and AI systems to uncover exposed credentials, verify third-party components, and assess pipeline integrity, producing a prioritized Security Posture Report with concrete remediation steps.

What is STRIDE threat modeling and when do I need it for cloud deployments?

STRIDE threat modeling is a structured framework for identifying security threats across modern software stacks and cloud deployments. You need it to quantify security posture gaps, enable vulnerability discovery, and produce action-oriented defenses adhering to OWASP Top 10.

How do I audit LLM and AI systems for prompt-injection risks?

Auditing LLM and AI systems for prompt-injection risks involves evaluating model exposure, tool-call permissions, and AI security gaps. This Skill detects prompt-injection vulnerabilities and includes them in a Security Posture Report with severity ratings.

Does the security audit work for daily automated checks or only comprehensive reviews?

The security audit supports both daily automated checks and comprehensive reviews. It operates in a daily mode with an 8/10 confidence gate for quick checks and a comprehensive mode with a 2/10 bar for deep infrastructure security audits.

What's the best way to generate a prioritized remediation plan for infrastructure security gaps?

The best way to generate a prioritized remediation plan is to run a security posture audit across secrets, dependencies, CI/CD, and AI systems. The Skill applies active verification and outputs a Security Posture Report with severity ratings and concrete fixes.

Can I use this to scan my automation skills ecosystem for security vulnerabilities?

Yes, you can use this to scan your automation skills ecosystem. The Skill includes supply chain scanning capabilities to evaluate the security of the automation skills ecosystem and dependencies, detecting risky transitive dependencies.