cso

Score security posture across infrastructure, dependencies, and supply chain.

Updated Apr 3, 2026
One-click install
npx skills add https://github.com/Intension-us/attention-diagnostic --skill cso-intension-us
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Intension-us/attention-diagnostic/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/Intension-us/attention-diagnostic --skill cso-intension-us

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Chief Security Officer audit identifies and surfaces security posture gaps across infrastructure, dependencies, and the software supply chain, helping teams reduce risk before it reaches production.

Core Features & Use Cases

  • Infrastructure-first security assessment covering CI/CD pipelines, secret management, and deployment security.
  • Dependency and supply chain scanning to detect vulnerable or tampered components.
  • Active verification, threat modeling (OWASP Top 10, STRIDE), and repeatable risk scoring for ongoing posture improvement.

Quick Start

Invoke the cso daily audit to start a zero-noise security posture review across your CI/CD stack.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a security audit for CI/CD pipelines and software supply chain?

A security audit assesses infrastructure, dependencies, and software supply chain components to identify and score deployment risks. It evaluates CI/CD pipelines and secret management to surface posture gaps before production release.

What is threat modeling with OWASP Top 10 coverage for infrastructure security?

Threat modeling with OWASP Top 10 coverage systematically identifies application and infrastructure vulnerabilities using frameworks like STRIDE. It provides repeatable risk scoring to actively verify and improve ongoing security posture.

Can I run a daily security posture review without generating excessive noise?

Yes, you can run a zero-noise daily security posture review by applying a higher scoring bar (8/10) to focus on critical risks. This mode targets daily CSO reviews across your CI/CD stack.

How do I detect vulnerable or tampered dependencies in my software supply chain?

Dependency and supply chain scanning detects vulnerable or tampered third-party components by evaluating your software supply chain. It scores security posture across infrastructure and dependencies to reveal real deployment risk.

What is the difference between a daily security audit and a comprehensive deep scan?

A daily audit uses an 8/10 scoring bar for zero-noise posture reviews, while a comprehensive deep scan applies a 2/10 bar for monthly, in-depth analysis across code, config, and third-party components.