cso

Identify and mitigate security posture risks across infrastructure, supply chain, and CI/CD pipelines.

Updated Apr 6, 2026
One-click install
npx skills add https://github.com/JeremiahEllington/NoahEllington --skill cso-jeremiahellington
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/JeremiahEllington/NoahEllington/tree/main/.claude/skills/cso
Command: npx skills add https://github.com/JeremiahEllington/NoahEllington --skill cso-jeremiahellington

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode focuses infrastructure-first security audits across secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification to ensure a robust security posture.

Core Features & Use Cases

  • Infra-first security audit to identify secrets leakage, misconfigurations, exposure, and mismanaged access in infrastructure.
  • Dependency supply chain scanning to detect vulnerable or tampered libraries and SBOM gaps.
  • CI/CD pipeline security for tokens, credentials, and deployment gate checks; LLM/AI security controls.
  • Threat modeling and security best practices including OWASP Top 10 and STRIDE with actionable remediation plans.
  • Active verification with daily zero-noise checks and monthly deep scans plus trend tracking across audits.

Quick Start

Start a daily CSO audit to surface critical risks and enable ongoing security monitoring.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit for secrets exposure and misconfigurations?

Run an infrastructure security audit to identify secrets leakage, misconfigurations, exposure, and mismanaged access. The audit requires in-depth analysis of secrets archaeology and infrastructure to load results into context for remediation.

What is STRIDE threat modeling and when do I need it for CI/CD pipeline security?

STRIDE threat modeling is a structured approach to identify security risks across CI/CD pipelines, infrastructure, and supply chains. You need it for daily risk assessments and comprehensive monthly reviews to ensure robust security posture.

Can I use this to check dependency supply chain integrity and SBOM gaps?

Yes, you can check dependency supply chain integrity by scanning for vulnerable or tampered libraries and identifying SBOM gaps. The audit detects supply chain risks and loads the results into context for actionable remediation.

What's the best way to automate OWASP Top 10 risk assessments for daily and monthly reviews?

The best way to automate OWASP Top 10 risk assessments is running daily zero-noise checks for critical risks and monthly deep scans for trend tracking. This active verification ensures continuous monitoring of your security posture.

Does the security audit cover LLM and AI risk controls?

Yes, the security audit covers LLM and AI risk controls as part of its core features. It analyzes AI security controls alongside infrastructure, supply chain, and CI/CD pipeline security to ensure comprehensive risk mitigation.