What problem does it solve?
Secures software ecosystems by performing an infrastructure-first security audit that surfaces secrets, supply-chain risks, CI/CD vulnerabilities, and AI/LLM security gaps.
Core Features & Use Cases
- Secrets archaeology and credential discovery across repos, CI logs, and config.
- Dependency supply chain scanning for known vulnerabilities and weak transitive dependencies.
- CI/CD pipeline security checks, including misconfigurations and insecure workflows.
- LLM/AI security checks focusing on prompt safety, tool usage, and data handling.
- Skill supply chain scanning to detect unsafe or malicious skills.
- OWASP Top 10 and STRIDE threat modeling with active verification.
- Daily quick assessments and monthly deep scans with trend tracking.
Quick Start
Run /cso to start the daily audit, or /cso --comprehensive for a monthly deep scan.