cso

Audit infrastructure, dependencies, and AI tooling with a 14-phase security workflow.

Updated Mar 27, 2026
One-click install
npx skills add https://github.com/Jesse-L-M/scz-target-engine --skill cso-jesse-l-m
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Jesse-L-M/scz-target-engine/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/Jesse-L-M/scz-target-engine --skill cso-jesse-l-m

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security posture of software projects is often lax and incomplete. You need a repeatable, CSO-grade audit that uncovers secrets, supply-chain risks, and insecure configurations across infrastructure, code, and third-party dependencies.

Core Features & Use Cases

  • Infrastructure-first security audit: secrets archaeology, CI/CD security, and platform hardening.
  • Dependency and supply-chain scanning: detect vulnerable or tampered components and risky transitive dependencies.
  • Threat modeling and risk verification: OWASP Top 10 coverage, STRIDE analysis, and active verification with remediation guidance.
  • Modes and workflow: daily quick checks with 8/10 gate and comprehensive monthly deep scans with 2/10 bar, plus a guided, repeatable 14-phase process.

Quick Start

Tell Claude to run /cso to start a daily CSO-grade security audit.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a comprehensive security audit for infrastructure and code?

Run a comprehensive security audit by executing a 14-phase workflow that scans infrastructure, dependencies, and AI tooling. This process uncovers secrets, evaluates supply-chain risks, and applies threat modeling using OWASP Top 10 and STRIDE analysis.

What is secrets archaeology in CI/CD security?

Secrets archaeology is the process of scanning code and configurations during a security audit to uncover exposed credentials. It hardens your CI/CD pipeline by detecting vulnerable components and risky transitive dependencies across your infrastructure.

Can I perform a daily quick security scan instead of a monthly deep audit?

You can perform daily quick security scans using an 8/10 gate threshold, or run comprehensive monthly deep audits with a stricter 2/10 bar. Both modes use the same guided, repeatable 14-phase process to verify your security posture.

Does this threat modeling approach cover OWASP Top 10 and STRIDE analysis?

Yes, the threat modeling approach explicitly covers OWASP Top 10 and STRIDE analysis. It actively verifies risks across your code and infrastructure, providing specific remediation guidance to harden your software security posture.

Do I need external tools to scan supply-chain and transitive dependencies?

No external dependencies are required to start scanning supply-chain risks. The audit supports tool-based checks guided by frontmatter configuration to detect vulnerable components and risky transitive dependencies natively.

What's the best way to harden platform security configurations?

The best way to harden platform security configurations is through a CSO-grade audit framework. It systematically evaluates insecure configurations across infrastructure, code, and third-party dependencies to provide targeted remediation guidance.