cso

Identify security posture weaknesses across infrastructure, supply chain, and application layers.

1|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/martin-hsu-test/gstack-gemini-slim --skill cso-martin-hsu-test
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/martin-hsu-test/gstack-gemini-slim/tree/main/.gemini/skills/gstack-cso
Command: npx skills add https://github.com/martin-hsu-test/gstack-gemini-slim --skill cso-martin-hsu-test

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Infrastructure-first security audits to uncover secrets, dependency risks, CI/CD vulnerabilities, and AI/LLM security gaps. Track risk trends across audit runs and provide a repeatable posture-checking workflow for security teams and engineers.

Core Features & Use Cases

  • Dual-mode scans: daily zero-noise checks for quick risk signals and monthly comprehensive scans for deep risk visibility.
  • Covers infrastructure, supply chain, and application layers with OWASP Top 10, STRIDE threat modeling, secret scanning, and active verification.
  • Use Case: run a daily audit to surface exposed credentials, insecure dependencies, and misconfigurations; then review trends to guide remediation.

Quick Start

Run a daily security audit against your repository to surface secrets, dependency risks, and CI/CD security gaps.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit infrastructure and supply chain security posture for exposed secrets and dependency risks?

Infrastructure and supply chain security posture audits identify exposed credentials, insecure dependencies, and CI/CD misconfigurations. Dual-mode scans run daily zero-noise checks and monthly comprehensive audits across cloud environments and code changes.

What is STRIDE threat modeling and how does it work with OWASP Top 10 checks?

STRIDE threat modeling and OWASP Top 10 checks identify and report security posture weaknesses across application layers. They systematically categorize threats and verify vulnerabilities during comprehensive monthly audits to provide deep risk visibility.

Can I track security risk trends across multiple CI/CD pipeline audit runs?

Yes, you can track security risk trends across CI/CD pipeline audit runs. The posture-checking workflow records risk signals from daily and monthly scans, guiding remediation by surfacing recurring dependency vulnerabilities and exposed secrets over time.

What's the best way to run a quick daily security check for cloud environments without noise?

Daily zero-noise security checks for cloud environments run lightweight scans to surface quick risk signals. They target exposed credentials, insecure dependencies, and CI/CD security gaps without deep verification, providing immediate actionable risk alerts.

Does secret scanning cover AI and LLM security gaps in application layers?

Secret scanning covers AI and LLM security gaps by identifying exposed credentials and misconfigurations across application layers. Combined with STRIDE threat modeling and OWASP Top 10 checks, it uncovers vulnerabilities during comprehensive monthly audits.

When should I not use lightweight daily audits instead of comprehensive monthly security scans?

Avoid using lightweight daily audits when you need deep risk visibility across infrastructure, supply chain, and application layers. Daily checks surface quick risk signals, but comprehensive monthly scans perform active verification and STRIDE threat modeling for thorough remediation.