cso

Identifies and reports security gaps across code, dependencies, CI/CD pipelines, and AI/LLM workflows.

Updated Apr 13, 2026
One-click install
npx skills add https://github.com/legotec73/gstack --skill cso-legotec73
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/legotec73/gstack/tree/main/cso
Command: npx skills add https://github.com/legotec73/gstack --skill cso-legotec73

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure and software teams struggle to perform repeatable, end-to-end security audits that cover code, dependencies, CI/CD pipelines, and AI/LLM workflows. This Skill provides a structured CSO-style framework to surface risks, model threats, and verify security controls across the software lifecycle.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10 and STRIDE threat modeling with active verification.
  • Two modes: daily zero-noise checks (8/10 confidence gate) and comprehensive monthly deep scans (2/10 bar). Trend tracking across audit runs.
  • Produces a Security Posture Report with concrete findings and remediation plans for stakeholders.

Quick Start

Run a daily CSO audit on your current project to begin collecting risk findings.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my code, dependencies, and CI/CD pipelines?

To perform a security audit, this Skill runs structured scans across code, dependencies, and CI/CD pipelines to identify gaps. It generates a Security Posture Report with concrete findings and remediation guidance aligned with OWASP Top 10.

What is STRIDE threat modeling and how does it apply to software security audits?

STRIDE threat modeling is a framework for identifying security threats, applied here to actively verify security controls across software workflows. It surfaces risks across code, dependencies, and CI/CD pipelines, producing a structured Security Posture Report.

Can I use this security audit for quick daily checks and comprehensive monthly scans?

Yes, you can use this security audit for both daily quick checks and monthly deep scans. Daily checks enforce an 8/10 confidence gate for zero-noise findings, while monthly scans lower the bar to 2/10 to enable comprehensive risk management.

Does this audit cover LLM and AI workflow security risks?

Yes, this audit covers LLM and AI workflow security risks by including dedicated scanning for AI workflows. It surfaces vulnerabilities across the software lifecycle, integrating these findings into the final Security Posture Report.

What is the best way to find leaked secrets and analyze my dependency supply chain?

The best way to find leaked secrets and analyze your dependency supply chain is through secrets archaeology and supply chain analysis. This Skill scans infrastructure and dependencies to surface hidden risks and generate remediation plans.

When should I not use a zero-noise daily security check?

You should not use a zero-noise daily security check when you need a comprehensive monthly deep scan. Daily checks apply an 8/10 confidence gate to suppress low-certainty findings, whereas monthly scans lower the threshold to 2/10 for full visibility.