cso

Audit software infrastructure for secrets, dependencies, CI/CD, and LLM security.

Updated Jun 4, 2026
One-click install
npx skills add https://github.com/Manzueti/cyberdart --skill cso-manzueti
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Manzueti/cyberdart/tree/main/cso
Command: npx skills add https://github.com/Manzueti/cyberdart --skill cso-manzueti

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Read, Grep, Glob, Write, Agent, WebSearch, AskUserQuestion, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive security audit, identifying vulnerabilities and weaknesses in software infrastructure.

Core Features & Use Cases

  • Infrastructure-First Security Audit: Performs a thorough audit of software infrastructure, including secrets archaeology, dependency supply chain, CI/CD pipeline security, and LLM/AI security.
  • Daily and Comprehensive Scans: Offers two modes of scanning: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar).
  • Trend Tracking: Tracks trends across audit runs for continuous improvement.
  • Use Case: Ideal for security audits, threat modeling, pentest reviews, OWASP reviews, and CSO reviews.

Quick Start

Run the cso skill to initiate a security audit of your infrastructure.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a comprehensive infrastructure security audit for secrets and CI/CD pipeline vulnerabilities?

An infrastructure security audit evaluates secrets, dependency supply chains, CI/CD pipelines, and LLM/AI security. It identifies vulnerabilities and weaknesses across your software infrastructure using daily and comprehensive scanning modes.

What is secrets archaeology in the context of a CI/CD pipeline security audit?

Secrets archaeology is a security audit phase that uncovers hidden or leaked credentials within your software infrastructure. It evaluates your codebase to identify exposed secrets before they can be exploited.

How do I set up daily vulnerability scanning with trend tracking for my software infrastructure?

Daily vulnerability scanning uses a zero-noise mode with an 8/10 confidence gate to surface only high-priority issues. It tracks trends across audit runs to help you monitor continuous security improvements over time.

Does this security audit cover OWASP reviews and LLM/AI security vulnerabilities?

Yes, the security audit covers OWASP reviews and includes specific LLM/AI security vulnerability scanning. It is designed for threat modeling and pentest reviews to comprehensively evaluate your infrastructure.

What is the difference between daily and comprehensive vulnerability scanning modes?

Daily scanning operates with a zero-noise 8/10 confidence gate for high-priority alerts, while comprehensive scanning performs a monthly deep scan with a 2/10 confidence bar to uncover broader infrastructure weaknesses.

Related Skills