cso

Audit codebases for secrets, supply-chain, CI/CD, and AI security risks.

Updated Apr 24, 2026
One-click install
npx skills add https://github.com/MissTully/Gstack --skill cso-misstully
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/MissTully/Gstack/tree/main/cso
Command: npx skills add https://github.com/MissTully/Gstack --skill cso-misstully

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides an infrastructure-first security audit capability, focusing on secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, and active verification to keep AI-powered systems safe and compliant.

Core Features & Use Cases

  • Secrets archaeology: identify leaked or embedded credentials across repositories and history.
  • Dependency supply chain: verify third-party components for known vulnerabilities and tampering.
  • CI/CD & runtime security: assess pipelines, access controls, and supply chain integrity.
  • LLM/AI security: test prompt safety, data access, and model risk in AI workflows.
  • Compliance & risk reporting: generate actionable remediation plans and risk dashboards for audits.

Quick Start

Run a daily CSO audit on the repository to identify secrets, supply-chain risks, and OWASP threats.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit for leaked secrets in my codebase?

A security audit for secrets identifies leaked or embedded credentials across repositories and history. This approach performs secrets archaeology to actively verify and keep AI-powered systems safe and compliant.

How do I check my dependency supply chain for known vulnerabilities?

Checking your dependency supply chain verifies third-party components for known vulnerabilities and tampering. The audit applies active verification to enforce safe handling of sensitive data across cloud deployments.

What is the best way to secure LLM and AI workflows against prompt injection?

Securing LLM and AI workflows involves testing prompt safety, data access, and model risk. An infrastructure-first audit tests these boundaries to enforce OWASP Top 10 compliance and safe sensitive data handling.

Can I use this security audit for daily health checks on cloud deployments?

Yes, you can use this security audit for daily health checks on cloud deployments. It applies to daily health checks, risk assessments, and compliance reviews with configurable scan thresholds and explicit guardrails.

Does the audit support STRIDE threat modeling for CI/CD pipeline security?

Yes, the audit supports STRIDE threat modeling for CI/CD pipeline security. It assesses pipelines, access controls, and supply chain integrity while enforcing checks for STRIDE and OWASP Top 10.

How do I generate a compliance risk report after finding vulnerabilities?

Generating a compliance risk report involves creating actionable remediation plans and risk dashboards for audits. The audit produces these outputs to support compliance reviews for AI-enabled projects.