cso

Audit infrastructure security across the stack for weaknesses and misconfigurations.

Updated Apr 13, 2026
One-click install
npx skills add https://github.com/mgher668/surf-ai --skill cso-mgher668
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/mgher668/surf-ai/tree/main/.agents/skills/gstack/cso
Command: npx skills add https://github.com/mgher668/surf-ai --skill cso-mgher668

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides infrastructure-first security auditing across the stack, including secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification to improve security posture, track findings, and drive remediation.

Core Features & Use Cases

  • Infrastructure-first security audit across the stack
  • Secrets archaeology, dependency supply chain, CI/CD pipeline security
  • LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling
  • Active verification and trend tracking across audit runs
  • Use cases: security audit, threat model, pentest review, OWASP, CSO review

Quick Start

Run the cso audit in daily mode to start an infrastructure-first security review across your stack.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit across my stack for OWASP Top 10 compliance?

An infrastructure security audit scans your stack for misconfigurations and weaknesses, applying OWASP Top 10 checks, STRIDE threat modeling, and secrets archaeology to identify vulnerabilities and track remediation.

What is the best way to perform STRIDE threat modeling and secrets archaeology in a CI/CD pipeline?

The best way to perform STRIDE threat modeling and secrets archaeology is through an infrastructure-first security audit that scrutinizes CI/CD pipelines, dependency supply chains, and active configurations to drive remediation.

Can I use this security audit for LLM/AI security and skill supply chain scanning?

Yes, this security audit supports LLM/AI security and skill supply chain scanning alongside dependency scrutiny, allowing you to identify vulnerabilities across emerging AI infrastructure and traditional stack components.

How do I start a daily security review to improve my infrastructure posture and track findings?

Start a daily security review by running an infrastructure-first audit across your environments, which actively verifies configurations, tracks findings across runs, and generates trend data to drive remediation.

Does this threat modeling approach support active verification using gstack workflows?

Yes, this threat modeling approach supports active verification using gstack workflows to continuously validate your security posture, track findings across audit runs, and enforce infrastructure compliance.

When should I use an infrastructure-first security audit instead of a general vulnerability scan?

Use an infrastructure-first security audit instead of a general scan when you need deep CI/CD pipeline security, STRIDE threat modeling, and supply chain scrutiny across environments to track and remediate systemic weaknesses.