cso

Audit infrastructure, dependencies, CI/CD, and AI risk with OWASP Top 10 and STRIDE.

9|3|Updated Jan 29, 2022
One-click install
npx skills add https://github.com/I194/PMTools_2.0 --skill cso-i194
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/I194/PMTools_2.0/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/I194/PMTools_2.0 --skill cso-i194

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning.
  • OWASP Top 10, STRIDE threat modeling, and active verification across audits.
  • Two modes: daily zero-noise (8/10 confidence) and comprehensive monthly scans with trend tracking.

Quick Start

Invoke the /cso audit to start a daily zero-noise security review.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit that covers infrastructure, dependencies, and CI/CD pipelines?

An infrastructure-first security audit assesses secrets, dependency supply chains, CI/CD pipelines, and LLM/AI risks. It applies OWASP Top 10, STRIDE threat modeling, and active verification to catch threats across your software project.

What is the difference between daily zero-noise and comprehensive monthly security scans?

Daily zero-noise security scans operate at an 8/10 confidence threshold to surface only high-priority threats, while comprehensive monthly scans perform deep audits with trend tracking to monitor security posture improvements over time.

Can I use STRIDE threat modeling and OWASP Top 10 for pentest preparation?

Yes, STRIDE threat modeling and OWASP Top 10 checks are integrated into the security audit. They support pentest preparation, security reviews, and supply-chain assessments by actively verifying vulnerabilities.

Does DevSecOps supply-chain scanning cover secrets archaeology and LLM security?

Yes, supply-chain scanning includes secrets archaeology to find exposed credentials and LLM/AI security to evaluate model risks. It scans skill supply chains and dependencies to ensure DevSecOps coverage across all project components.

What is the best way to start a zero-noise security review for a software project?

The best way to start a zero-noise security review is to invoke the daily audit command within the required gstack CSO workflow. This initiates an infrastructure-first scan targeting high-confidence threats without alert fatigue.