cso

Audit infrastructure, dependencies, CI/CD, and AI workflows for security weaknesses.

Updated Mar 31, 2026
One-click install
npx skills add https://github.com/huichen/gstack --skill cso-huichen
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/huichen/gstack/tree/main/cso
Command: npx skills add https://github.com/huichen/gstack --skill cso-huichen

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure and software supply chain pose real security risk; this Skill provides a structured Chief Security Officer level audit covering secrets archaeology, dependency supply chain, CI/CD security, LLM/AI security, skill supply chain scanning, and standard threat modeling like OWASP Top 10 and STRIDE.

Core Features & Use Cases

  • Infrastructure-first security audit: continuous, structured checks across environments, pipelines, and deployment tooling.
  • Dependency and supply chain risk: identify leaked credentials, stale keys, and risky third-party components.
  • Active verification & threat modeling: OWASP Top 10, STRIDE, and remediation guidance with concrete steps for developers and operators.

Quick Start

Run the cso daily audit to begin a security posture review across infra, code, and dependencies.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a comprehensive security audit for my code and dependencies?

A comprehensive security audit reviews your dependencies, CI/CD pipelines, and code paths to identify weaknesses. It applies OWASP Top 10, STRIDE threat modeling, and secrets scanning to deliver a prioritized remediation plan with concrete steps and risk ratings.

What is STRIDE threat modeling and how does it apply to CI/CD security?

STRIDE threat modeling identifies threats like spoofing, tampering, and denial of service across system components. Applied to CI/CD security, it maps threats to pipeline stages and deployment tooling, producing structured risk ratings and remediation guidance for developers and operators.

How do I identify leaked credentials and risky third-party components in my supply chain?

Supply chain risk scanning identifies leaked credentials, stale keys, and risky third-party components by analyzing your dependency graph and infrastructure. It flags vulnerable packages and secrets archaeology, mapping findings to industry best practices for immediate remediation.

Does this security audit cover AI and LLM workflows?

Yes, the security audit covers LLM and AI workflows, including skill supply chain scanning. It evaluates AI/LLM security postures alongside infrastructure and standard code paths to identify weaknesses and generate concrete remediation steps.

Can I run automated OWASP Top 10 checks across my infrastructure and deployment tooling?

Yes, infrastructure-first security audits run structured checks across environments, pipelines, and deployment tooling. They apply OWASP Top 10 mappings to identify vulnerabilities and generate a prioritized remediation plan with risk ratings.

What is the difference between daily and comprehensive security posture review modes?

Daily mode provides continuous, structured checks across environments and pipelines for ongoing security posture review. Comprehensive mode applies full STRIDE threat modeling, OWASP Top 10 mappings, and deep secrets archaeology to deliver a complete prioritized remediation plan.