cso

Identify and catalog security risks across code, dependencies, CI/CD, and infrastructure.

1|2|Updated Jan 4, 2024
One-click install
npx skills add https://github.com/NaKMiers/Port4lio --skill cso-nakmiers
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/NaKMiers/Port4lio/tree/main/.agents/skills/cso
Command: npx skills add https://github.com/NaKMiers/Port4lio --skill cso-nakmiers

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Reduces blind spots in security posture by performing structured, multi-domain audits across infrastructure, CI/CD, dependencies, and code. It identifies misconfigurations, leaked secrets, and weak controls so teams can act.

Core Features & Use Cases

  • Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs.

Quick Start

Run a full daily audit using the /cso command to begin the 8/10 confidence gate.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my codebase for leaked secrets and dependency vulnerabilities?

To audit security posture, you can run a daily scan to identify leaked secrets and dependency vulnerabilities across code and supply chains. This structured audit applies an 8/10 confidence gate to filter noise and surface actionable exposures.

What is the best way to check OWASP Top 10 coverage during a threat modeling review?

Checking OWASP Top 10 coverage during a threat modeling review involves applying STRIDE methodology across code and infrastructure. This process identifies misconfigurations and weak controls, ensuring comprehensive security risk cataloging.

Can I use a single tool for CI/CD pipeline security and LLM security audits?

Yes, you can audit both CI/CD pipeline security and LLM/AI security within a single multi-domain scan. It identifies misconfigurations and weak controls across modern software stacks, covering infrastructure, dependencies, and AI considerations.

Does active verification work for daily security posture checks without generating alert fatigue?

Active verification works for daily security posture checks by applying a zero-noise 8/10 confidence gate. This ensures only high-certainty exposures are surfaced, preventing alert fatigue while maintaining continuous risk identification.

When should I run a comprehensive supply chain audit instead of a daily scan?

You should run a comprehensive supply chain audit monthly for deep scans that track trends across audit runs. Unlike the daily zero-noise check, this comprehensive mode lowers the confidence bar to 2/10 to uncover deeper, systemic exposures.