What problem does it solve?
Manual security auditing across infrastructure, dependencies, CI/CD pipelines, and LLM/AI systems is fragmented, time-consuming, and prone to missed gaps that leave teams exposed to preventable vulnerabilities.
Core Features & Use Cases
- Dual-mode security audits: Run zero-noise daily scans with an 8/10 confidence gate for routine checks, or comprehensive monthly deep scans with a 2/10 confidence bar for full coverage, with trend tracking across all audit runs.
- Full-scope security checks: Covers secrets archaeology, dependency supply chain scanning, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10 validation, and STRIDE threat modeling with active verification.
- Use Case: A team launching a new LLM-powered feature can use this skill to run a single end-to-end audit covering the model's supply chain, associated deployment pipelines, and OWASP Top 10 risks in one workflow, instead of running disjointed manual checks.
Quick Start
Ask the cso skill to run a full security audit of your current project's infrastructure, dependencies, and CI/CD pipeline.