cso

Scan secrets, supply chains, CI/CD pipelines, and LLM/AI security.

1|Updated Mar 31, 2026
One-click install
npx skills add https://github.com/LaPaGaYo/nexus --skill cso-lapagayo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/LaPaGaYo/nexus/tree/main/skills/support/cso
Command: npx skills add https://github.com/LaPaGaYo/nexus --skill cso-lapagayo

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides an infrastructure-first security auditing workflow that systematically scans for secrets, supply chain risks, CI/CD vulnerabilities, and adversarial AI threats across skill and host surfaces.

Core Features & Use Cases

  • Secrets archaeology and dependency-supply-chain checks across pipelines and skill surfaces.
  • OSINT-like threat modeling, OWASP Top 10 alignment, and governance checks integrated into lifecycle reviews.
  • Guided remediation workflows with deterministic steps and integration with nexus.skill.yaml manifests.

Quick Start

Invoke a comprehensive security audit on your Nexus-enabled environment and follow the prompts to start the dual-audit workflow.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits for infrastructure and CI/CD pipelines?

Automate infrastructure security audits by scanning secrets, dependency supply chains, and CI/CD pipelines across Nexus-hosted hosts and skill surfaces. This workflow systematically detects vulnerabilities and provides actionable remediation during lifecycle reviews.

What is threat modeling for LLM and AI security in skill supply chains?

Threat modeling for LLM and AI security involves scanning skill supply chains for adversarial AI threats and OSINT-like risks aligned with OWASP Top 10. It systematically identifies potential attack vectors across skill and host surfaces during governance checks.

Can I use nexus.skill.yaml manifests for governance checks during security audits?

Yes, you can use nexus.skill.yaml manifests for governance checks during security audits. The auditing workflow integrates with these manifests to apply deterministic audit steps via scripts across your Nexus-enabled environment.

Does infrastructure security auditing work with YAML frontmatter-driven configuration?

Yes, infrastructure security auditing works with YAML frontmatter-driven configuration requiring a mandatory name and description. It uses this configuration to apply deterministic audit steps across Nexus-hosted hosts and skill surfaces.

What is the best way to scan for secrets and dependency supply chain risks across pipelines?

The best way to scan for secrets and dependency supply chain risks is using an infrastructure-first security auditing workflow. It performs secrets archaeology and dependency-supply-chain checks across pipelines and skill surfaces with guided remediation.