cso

Audit infrastructure security posture and generate a Security Posture Report with severity ratings.

Updated Apr 5, 2026
One-click install
npx skills add https://github.com/makyua-san/usecase-agent --skill cso-makyua-san
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/makyua-san/usecase-agent/tree/main/.claude/skills/cso
Command: npx skills add https://github.com/makyua-san/usecase-agent --skill cso-makyua-san

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides an infrastructure-first security audit approach. It targets secrets archaeology, dependency supply chain weaknesses, CI/CD pipeline security gaps, LLM/AI security risks, skill supply chain vulnerabilities, and standard frameworks like OWASP Top 10 and STRIDE, with active verification. Two modes—daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 gate). Trend tracking across audit runs helps teams continuously improve.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets, dependencies, CI/CD, LLM/AI security, and supply chain risk.
  • Threat modeling and risk scoring using OWASP Top 10, STRIDE, and actionable remediation plans.
  • Daily and comprehensive scan modes with trend tracking for ongoing security posture improvement.

Quick Start

Use the cso skill to initiate a security posture audit and generate a prioritized remediation plan.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit for secrets and CI/CD weaknesses?

Infrastructure security audits identify secrets, dependency supply chain risks, and CI/CD pipeline gaps. The process scans your environment using Bash and WebSearch, applying OWASP Top 10 and STRIDE frameworks to generate a Security Posture Report with severity ratings and actionable remediation plans.

What is threat modeling using STRIDE and OWASP Top 10 for risk management?

Threat modeling using STRIDE and OWASP Top 10 systematically identifies and scores security risks across your infrastructure. It correlates findings from secrets, dependencies, and LLM integrations to produce prioritized, actionable remediation guidance for continuous security posture improvement.

How do I audit LLM security and dependency supply chain risks?

Auditing LLM security and dependency supply chain risks involves scanning infrastructure for exposed secrets and vulnerable packages. It applies active verification to identify AI security gaps and supply chain weaknesses, outputting a comprehensive report with confidence-gated findings and remediation steps.

Can I run daily security scans without generating excessive false positives?

Daily security scans operate with a zero-noise approach and an 8/10 confidence gate to eliminate excessive false positives. This mode actively verifies threats across secrets and dependencies, ensuring only high-confidence vulnerabilities are surfaced for immediate remediation.

What is the best way to track security posture improvements over time?

Tracking security posture improvements over time is best achieved through trend tracking across daily and comprehensive audit runs. By comparing monthly deep scans with zero-noise daily scans, teams monitor risk reduction and continuously update their remediation plans.