cso

Audit infrastructure security across secrets, dependencies, CI/CD, and LLM/AI systems.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/ligianehua/Gstack --skill cso-ligianehua
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/ligianehua/Gstack/tree/main/cso
Command: npx skills add https://github.com/ligianehua/Gstack --skill cso-ligianehua

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode facilitates infrastructure-first security audits, covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning, with OWASP Top 10 and STRIDE threat modeling and active verification.

Core Features & Use Cases

  • Secrets archaeology: discover exposed credentials and sensitive data across code, history, and configuration.
  • Dependency supply chain analysis: assess third-party risk beyond standard scanners and SBOMs.
  • CI/CD pipeline security: verify pipeline integrity and configuration hygiene.
  • LLM/AI security checks: prompt hygiene, tool permissions, and access controls.
  • Skill supply chain scanning: evaluate installed AI skills and their safety.
  • Threat modeling: apply OWASP Top 10 and STRIDE to identify and mitigate risks.

Use cases include ongoing risk monitoring, post-incident forensics, and pre-release security reviews.

Quick Start

Run the daily infrastructure-first CSO audit with /cso to start continuous risk monitoring across your repo.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit using STRIDE and OWASP Top 10?

Apply infrastructure-first security audits using STRIDE threat modeling and OWASP Top 10 to identify and mitigate risks across codebases, pipelines, and vendor dependencies, outputting structured remediation guidance.

What is secrets archaeology and how does it find exposed credentials in my codebase?

Secrets archaeology discovers exposed credentials and sensitive data across code, commit history, and configuration files as part of a comprehensive infrastructure security posture review.

How do I secure my CI/CD pipeline and assess dependency supply chain risks?

Verify CI/CD pipeline integrity and configuration hygiene while assessing third-party dependency supply chain risks beyond standard scanners and SBOMs during continuous security monitoring.

Can I use this for LLM security and AI prompt hygiene checks?

Perform LLM and AI security checks covering prompt hygiene, tool permissions, and access controls, alongside scanning the installed AI skill supply chain to evaluate safety.

What is the difference between daily zero-noise checks and monthly deep security scans?

Daily infrastructure audits run at an 8/10 confidence threshold for zero-noise checks, while monthly deep scans lower the bar to 2/10 to surface broader potential vulnerabilities and track audit trends.

How do I start continuous risk monitoring for my repository?

Run the daily infrastructure-first CSO audit to start continuous risk monitoring across your repository, applicable for ongoing security reviews, post-incident forensics, and pre-release validations.