cso

Automate security audits for supply chains, infrastructure, and AI attack surfaces.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/KrismithReddy12/gstack --skill cso-krismithreddy12
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/KrismithReddy12/gstack/tree/main/cso
Command: npx skills add https://github.com/KrismithReddy12/gstack --skill cso-krismithreddy12

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This skill addresses the critical security gaps in modern AI-assisted development by automating comprehensive audits across the entire software supply chain, infrastructure, and LLM-specific attack surfaces.

Core Features & Use Cases

  • Infrastructure-First Auditing: Performs deep scans for leaked secrets, insecure CI/CD configurations, and shadow infrastructure.
  • AI/LLM Security: Specifically targets prompt injection vectors, unsanitized LLM output, and insecure tool-calling patterns.
  • Use Case: Before shipping a new production service, run this skill to automatically verify OWASP compliance, check for hardcoded credentials in git history, and validate that your CI/CD pipeline is protected against supply chain attacks.

Quick Start

Invoke the cso skill to perform a comprehensive security audit of the current repository.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits for LLM prompt injection and OWASP risks?

Automate security audits by running multi-phase verification logic that targets LLM prompt injection, unsanitized output, and OWASP Top 10 risks. This scans AI-specific attack surfaces to verify production-grade security posture in AI-assisted development environments.

Can I scan for leaked secrets and insecure CI/CD configurations in my software supply chain?

Yes, you can scan for leaked secrets and insecure CI/CD configurations. The audit performs deep infrastructure-first scans across the software supply chain to detect hardcoded credentials and validate pipeline protection against supply chain attacks.

What is the best way to check my repository for OWASP compliance before production deployment?

The best way to check OWASP compliance is to invoke an autonomous security audit. It automatically verifies OWASP compliance, checks git history for hardcoded credentials, and validates CI/CD pipeline security before shipping production services.

Does autonomous security auditing work for AI-specific attack surfaces like insecure tool-calling?

Yes, autonomous security auditing works for AI-specific attack surfaces. It specifically targets insecure tool-calling patterns, unsanitized LLM output, and prompt injection vectors to secure AI-assisted engineering workflows.

How do I detect shadow infrastructure and misconfigurations in my development environment?

Detect shadow infrastructure and misconfigurations by running infrastructure-first auditing. This performs deep scans to identify insecure CI/CD configurations, shadow infrastructure, and leaked secrets across the software supply chain.