What problem does it solve?
Security teams struggle to gain a cohesive view of an organization's risk posture across infrastructure, dependencies, and CI/CD pipelines. This Skill provides a centralized Security Posture Report with prioritized remediation guidance for leadership and engineering teams.
Core Features & Use Cases
- Infrastructure-first security audit: secrets archaeology, pipeline security, threat modeling, and active verification.
- Dependency supply chain analysis: identify vulnerable or tampered dependencies and suggest mitigations.
- LLM/AI security checks: guardrails for prompt handling, tool usage, and output safety in AI-assisted workflows.
- OWASP Top 10 & STRIDE threat modeling: structured risk assessment across systems and data flows.
- Modes: daily quick checks for near-term risk and comprehensive monthly scans for deeper coverage.
Quick Start
Run the daily audit with /cso for an 8/10 confidence gate, or /cso --comprehensive for a monthly deep scan.