What problem does it solve?
This skill addresses the critical security gaps in modern AI-assisted development by automating comprehensive audits across the entire software supply chain, infrastructure, and LLM-specific attack surfaces.
Core Features & Use Cases
- Infrastructure-First Auditing: Performs deep scans for leaked secrets, insecure CI/CD configurations, and shadow infrastructure.
- AI/LLM Security: Specifically targets prompt injection vectors, unsanitized LLM output, and insecure tool-calling patterns.
- Use Case: Before shipping a new production service, run this skill to automatically verify OWASP compliance, check for hardcoded credentials in git history, and validate that your CI/CD pipeline is protected against supply chain attacks.
Quick Start
Invoke the cso skill to perform a comprehensive security audit of the current repository.