cso

Audit infrastructure, dependencies, and code for security posture gaps.

Updated Mar 31, 2026
One-click install
npx skills add https://github.com/hetsheth-droid/toolbox-template --skill cso-hetsheth-droid
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/hetsheth-droid/toolbox-template/tree/main/incubating/gstack/cso
Command: npx skills add https://github.com/hetsheth-droid/toolbox-template --skill cso-hetsheth-droid

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security auditing to uncover secrets, supply-chain, and pipeline risks before they bite.

Core Features & Use Cases

  • Comprehensive CSO-style audits across infrastructure, dependencies, CI/CD, and AI systems.
  • OWASP Top 10, STRIDE threat modeling, secrets archaeology, and supply chain risk scoring.
  • Actionable remediation guidance with traceable evidence and risk-driven prioritization.

Quick Start

Run the /cso command to perform a daily security audit and review the resulting Security Posture Report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security posture audit across my infrastructure and code?

Security posture audits identify and report gaps across infrastructure, dependencies, and code by performing CSO-grade assessments. They score findings and produce actionable remediation guidance with verifiable evidence for daily risk verification.

What is STRIDE threat modeling and when do I need it for CI/CD security?

STRIDE threat modeling is a structured technique applied during security audits to systematically identify and categorize threats across CI/CD pipelines and AI systems. You need it for monthly deep-dive risk assessments and comprehensive vulnerability discovery.

How do I check my supply chain and dependencies for security risks?

You can check supply chain risks by executing an infrastructure-first security audit that uncovers secrets, supply-chain, and pipeline vulnerabilities. The audit scores dependencies and provides traceable evidence with risk-driven prioritization for remediation.

Does this security audit cover the OWASP Top 10 and LLM security vulnerabilities?

Yes, the security audit covers the OWASP Top 10 and LLM security by orchestrating daily risk verification and monthly deep-dive assessments. It applies CSO-grade auditing to identify and report posture gaps across AI systems and infrastructure.

What is the best way to find exposed secrets in my codebase and pipelines?

The best way to find exposed secrets is through secrets archaeology, a process included in comprehensive security posture audits. It uncovers hidden credentials across infrastructure and CI/CD pipelines before they cause security breaches.

Can I use these audits for both daily risk verification and monthly assessments?

Yes, you can use these audits for both daily risk verification and monthly deep-dive assessments. The audit orchestrates multiple phases to identify security posture gaps and generate actionable remediation guidance suited for both operational frequencies.