cso

Detect infrastructure-first security posture issues across repositories.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/JonOlsenCa/gstack-main --skill cso-jonolsenca
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/JonOlsenCa/gstack-main/tree/main/cso
Command: npx skills add https://github.com/JonOlsenCa/gstack-main --skill cso-jonolsenca

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode standardizes infrastructure-first security audits across codebases, focusing on secrets archaeology, dependency supply chain, CI/CD security, LLM/AI risk, and active verification to reduce blind spots.

Core Features & Use Cases

  • Infra-first security posture assessment across infrastructure, dependencies, and pipelines.
  • Threat modeling & risk visibility including OWASP Top 10, STRIDE, and mitigation plans.
  • Continuous and comprehensive scans with daily zero-noise checks and monthly deep assessments to track trends.

Quick Start

Run the daily CSO audit with /cso to begin a zero-noise security posture check across your repository.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a security audit to detect secrets and CI/CD vulnerabilities across my repository?

To automate a security audit and detect secrets archaeology, dependency supply chain risks, and CI/CD gaps, run a daily zero-noise security posture check. This enforces active verification and OWASP Top 10 alignment across your repository environments and teams.

What is STRIDE threat modeling and how does it apply to infrastructure security?

STRIDE threat modeling is a framework for identifying security threats like spoofing and repudiation. Applied to infrastructure security, it provides risk visibility and generates traceable mitigation plans to systematically reduce blind spots across your codebase.

How do I perform a dependency supply chain and LLM security risk assessment?

Perform a dependency supply chain and LLM security risk assessment by running a monthly deep audit. This evaluates infrastructure-first security posture, tracks remediation trends over time, and actively verifies AI/LLM security gaps within your repository.

Does the OWASP Top 10 audit cover multiple environments and team workflows?

Yes, OWASP Top 10 audits cover multiple environments and teams. The standardized assessment applies active verification to ensure comprehensive risk visibility and traceable remediation across diverse infrastructure and pipeline configurations.

What is the best way to track security posture trends without false positives?

The best way to track security posture trends without false positives is running daily zero-noise checks. This approach standardizes infrastructure-first security audits and provides traceable remediation tracking across monthly deep assessments.

When do I need a deep infrastructure security assessment instead of a daily check?

You need a deep infrastructure security assessment monthly or when auditing major changes, rather than relying solely on daily checks. Deep assessments evaluate broader dependency supply chain risks and LLM vulnerabilities while tracking remediation trends.