What problem does it solve?
Infrastructure and software teams struggle to perform repeatable, end-to-end security audits that cover code, dependencies, CI/CD pipelines, and AI/LLM workflows. This Skill provides a structured CSO-style framework to surface risks, model threats, and verify security controls across the software lifecycle.
Core Features & Use Cases
- Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10 and STRIDE threat modeling with active verification.
- Two modes: daily zero-noise checks (8/10 confidence gate) and comprehensive monthly deep scans (2/10 bar). Trend tracking across audit runs.
- Produces a Security Posture Report with concrete findings and remediation plans for stakeholders.
Quick Start
Run a daily CSO audit on your current project to begin collecting risk findings.