cso

Audit infrastructure for secrets, supply chain, CI/CD, and AI security gaps.

Updated May 14, 2026
One-click install
npx skills add https://github.com/lemig/transcriptor --skill cso-lemig
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/lemig/transcriptor/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/lemig/transcriptor --skill cso-lemig

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides infrastructure-first security audits to reveal secrets, supply-chain risks, CI/CD vulnerabilities, LLM/AI security gaps, and a transparent risk narrative across an organization's tech stack.

Core Features & Use Cases

  • Infrastructure-first security audit coverage across secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs.
  • Use cases include security audits, threat modeling, pentest review, OWASP assessments, and CSO-level governance.

Quick Start

Run a daily CSO audit on a project to surface secrets and supply-chain risks.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit for secrets and supply chain risks?

An infrastructure security audit scans codebases, pipelines, and deployments to uncover secrets, dependency supply chain risks, and CI/CD vulnerabilities. It requires integrating tooling for secret scanning and dependency checks to identify and verify infrastructure threats.

What is STRIDE threat modeling and when do I need it for CI/CD pipeline security?

STRIDE threat modeling is a structured approach to identifying security threats across CI/CD pipelines and deployments. You need it during comprehensive monthly deep scans to systematically uncover spoofing, tampering, and elevation of privilege risks in your infrastructure.

Can I use automated vulnerability verification for daily security monitoring?

Yes, automated vulnerability verification supports daily security monitoring by applying a zero-noise, 8/10 confidence gate to filter out false positives. This daily mode surfaces only high-confidence risks across your codebase and CI/CD pipelines.

Does this security audit approach cover LLM and AI security gaps?

Yes, the security audit explicitly includes LLM and AI security gap analysis alongside infrastructure, secrets, and supply chain scanning. It evaluates your AI integrations for vulnerabilities during both daily monitoring and comprehensive monthly deep scans.

What's the best way to run an OWASP Top 10 assessment across a tech stack?

The best way to run an OWASP Top 10 assessment is executing a comprehensive monthly deep scan with a 2/10 confidence bar. This mode captures broader risk narratives across codebases and deployments, tracking vulnerability trends over time.

What tool integrations do I need for dependency and secret scanning in pipelines?

You need dedicated tool integrations for secret scanning, dependency checks, CI/CD analysis, and risk verification. These tools feed data into the audit pipeline to enable active verification and enforce security policies across your infrastructure.