cso

Audit infrastructure security gaps across secrets, dependencies, CI/CD, and LLM/AI.

15|1|Updated Apr 4, 2026
One-click install
npx skills add https://github.com/howdeploy/NekoFree --skill cso-howdeploy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/howdeploy/NekoFree/tree/main/skills/cso
Command: npx skills add https://github.com/howdeploy/NekoFree --skill cso-howdeploy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits that surface secrets, dependency risks, and configuration weaknesses across CI/CD pipelines, AI integrations, and supply chains.

Core Features & Use Cases

  • Secrets archaeology: uncover leaked keys and credentials across repos and pipelines.
  • Dependency & supply chain security: identify vulnerable transitive dependencies and compromised components.
  • Threat modeling and OWASP/STRIDE analysis: map threats and verify mitigations across the stack.
  • Continuous and periodic scans: daily zero-noise checks and monthly deep audits, with trend tracking.

Quick Start

Run a daily security audit for your project to identify secrets, dependency risks, and OWASP threats.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit for secrets and dependency risks?

An infrastructure security audit identifies leaked credentials and vulnerable dependencies by performing deterministic checks across repositories and CI/CD pipelines. The Skill uncovers secrets archaeology and supply chain risks, producing actionable reports for immediate remediation.

Can I use OWASP and STRIDE analysis for continuous threat modeling in my CI/CD pipeline?

OWASP and STRIDE analysis map threats and verify mitigations across your infrastructure stack during CI/CD pipeline security checks. The Skill supports daily zero-noise scans and monthly comprehensive audits to track security posture trends across runs.

What is the best way to find leaked keys and credentials across my repositories?

Secrets archaeology finds leaked keys and credentials by scanning repositories and pipelines using Bash, Grep, and Glob tools. This process surfaces hidden authentication tokens and configuration weaknesses, enabling proactive remediation before exploitation.

Does this security audit tool support LLM and AI integration vulnerability checks?

LLM and AI security checks are supported as part of the comprehensive infrastructure security posture audit. The Skill identifies configuration weaknesses and vulnerabilities specific to AI integrations, ensuring threats are mapped and mitigated across the stack.

How do I run a daily zero-noise security scan without false positives?

Daily zero-noise security scans perform deterministic checks to identify infrastructure security gaps without alert fatigue. The Skill uses a defined toolset including Bash, Read, Grep, and Glob to execute precise vulnerability detection and generate actionable reports.

What tools do I need to run automated threat modeling and supply chain security scans?

Automated threat modeling and supply chain security scans require a defined toolset of Bash, Read, Grep, Glob, Write, Agent, WebSearch, and AskUserQuestion. These tools perform deterministic checks to identify vulnerable transitive dependencies and compromised components.