cso

Identify security weaknesses across infrastructure, dependencies, and software supply chains.

Updated Mar 28, 2026
One-click install
npx skills add https://github.com/mattothomas/sp26_hackpsu --skill cso-mattothomas
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/mattothomas/sp26_hackpsu/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/mattothomas/sp26_hackpsu --skill cso-mattothomas

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode for infrastructure-first security audits that reveal weaknesses in the system, dependencies, and supply chain.

Core Features & Use Cases

  • Daily 8/10 confidence gate security checks for rapid risk visibility across CI/CD, secrets archaeology, dependency supply chain, and LLM/AI security.
  • Comprehensive monthly deep scan for thorough threat modeling (OWASP Top 10, STRIDE) and active verification.
  • Use Case: A security team runs a daily audit to surface secrets in CI logs and stale keys, then runs a monthly deep audit to verify remediation.

Quick Start

Run a daily CSO audit on your infrastructure to surface secrets, supply-chain risks, and CI/CD weaknesses.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my CI/CD pipeline and software supply chain?

Run a security audit on your CI/CD pipeline and software supply chain by applying daily quick checks and monthly deep scans to surface secrets archaeology, dependency risk, and infrastructure weaknesses. The audit enforces confidence gates and provides concrete remediation guidance to raise your security posture.

What is threat modeling using OWASP and STRIDE for infrastructure security?

Threat modeling using OWASP and STRIDE for infrastructure security is a comprehensive deep scan process that identifies and verifies security weaknesses across your system. It applies active verification against the OWASP Top 10 to provide concrete remediation guidance for raising your overall security posture.

Can I use this approach to check for exposed secrets and stale keys in CI logs?

Yes, you can check for exposed secrets and stale keys in CI logs by running daily security audits designed for rapid risk visibility. This secrets archaeology process surfaces hidden credentials across your infrastructure and CI/CD pipelines to enforce an 8/10 confidence gate for daily checks.

Does this security audit support LLM and AI security risk management?

Yes, this security audit supports LLM and AI security risk management by including specific checks for AI vulnerabilities within both daily and comprehensive scans. It identifies dependency supply chain risks and AI-specific threats, enforcing configurable gates to provide actionable remediation guidance.

What is the best way to enforce confidence gates during infrastructure security checks?

The best way to enforce confidence gates during infrastructure security checks is to apply an 8/10 threshold for daily rapid risk visibility and a 2/10 threshold for comprehensive monthly deep scans. This configurable gating mechanism ensures vulnerabilities are verified before providing remediation guidance.