cso

Audit infrastructure, dependencies, and AI workflows for security weaknesses.

2|Updated Mar 31, 2026
One-click install
npx skills add https://github.com/jayzalowitz/skytwin --skill cso-jayzalowitz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/jayzalowitz/skytwin/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/jayzalowitz/skytwin --skill cso-jayzalowitz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audit that reveals secrets, supply chain risks, and insecure configurations across CI/CD and LLM workflows.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD security, LLM/AI security, and skill supply chain scanning.
  • OWASP Top 10 compliance, STRIDE threat modeling, and active verification across audit runs.
  • Two modes: daily with zero-noise gating at 8/10 confidence, and comprehensive monthly deep scan with 2/10 barrier, with trend tracking across runs.

Quick Start

Run the daily cso audit to perform an infrastructure-wide security posture check including secrets archaeology and supply-chain review.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my infrastructure for leaked secrets and supply chain risks?

Infrastructure security audits surface leaked secrets and supply chain risks by scanning dependencies and CI/CD workflows. This skill performs secrets archaeology and dependency analysis to reveal insecure configurations across your infrastructure.

What is the best way to check LLM and AI workflow security posture?

Checking LLM and AI workflow security posture involves scanning skill supply chains and validating configurations. This audit performs LLM security analysis and skill supply chain scanning to surface weaknesses in your AI workflows.

How does STRIDE threat modeling integrate with an OWASP Top 10 compliance check?

STRIDE threat modeling integrates with OWASP Top 10 checks by evaluating infrastructure threats alongside web vulnerability categories. The audit applies both frameworks during active verification to validate security findings.

Can I run a daily security audit without being overwhelmed by false positives?

Daily security audits can run with zero-noise gating at an 8/10 confidence threshold to minimize false positives. This mode performs infrastructure-wide checks including secrets archaeology and supply-chain review.

When do I need a comprehensive monthly deep scan versus a daily security audit?

A comprehensive monthly deep scan is needed for thorough vulnerability validation using a 2/10 confidence barrier, unlike daily audits. It tracks security posture trends across runs while actively verifying comprehensive findings.

Does the audit actively verify security weaknesses or just report static analysis findings?

The audit actively verifies security weaknesses rather than just reporting static analysis findings. It uses active verification across both daily and comprehensive monthly runs to validate discovered threats and configuration issues.