cso

Audits infrastructure and supply chain for secrets, dependency risks, misconfigurations, and vulnerabilities using threat modeling and scanning workflows.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/nhattran998/personal-athlete-agent --skill cso-nhattran998
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/nhattran998/personal-athlete-agent/tree/main/.agents/skills/gstack-cso
Command: npx skills add https://github.com/nhattran998/personal-athlete-agent --skill cso-nhattran998

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Chief Security Officer mode provides infrastructure-first security audits that uncover secrets, insecure dependencies, CI/CD risks, LLM/AI security gaps, skill supply chain issues, and OWASP/STRIDE threats, with built-in verification.

Core Features & Use Cases

  • Daily security checks (zero-noise, 8/10 confidence gate) for ongoing risk monitoring.
  • Comprehensive monthly scans for deep risk assessment and trend tracking.
  • Threat modeling, secret archaeology, and supply-chain security across the tech stack.

Quick Start

Activate gstack-cso with /cso to run a daily security audit across your infrastructure and supply chain.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a CI/CD security audit and identify secrets in my infrastructure?

Run a CI/CD security audit to identify secrets, dependency risks, and misconfigurations by implementing STRIDE threat modeling and OWASP Top 10 guidance. It actively verifies vulnerability vectors across your supply chain to surface actionable remediation.

What is STRIDE threat modeling and how does it apply to software supply chain security?

STRIDE threat modeling is a framework applied to software supply chain security to uncover spoofing, tampering, and information disclosure risks. It maps OWASP Top 10 threats across CI/CD pipelines and infrastructure to guide targeted remediation.

Can I use this for daily dependency security checks without generating excessive noise?

Yes, you can run daily dependency security checks with a zero-noise 8/10 confidence gate for ongoing risk monitoring. It actively verifies dependency risks and surfaces only actionable remediation without overwhelming alerts.

How do I perform secret archaeology and dependency auditing across my tech stack?

Perform secret archaeology and dependency auditing by scanning infrastructure and third-party integrations for exposed credentials and insecure packages. It applies OWASP guidance to discover vulnerabilities and verify active threats across the supply chain.

Does this security audit work for both quick health checks and comprehensive monthly scans?

Yes, this security audit works for both daily zero-noise health checks and comprehensive monthly scans. It scales from ongoing risk monitoring to deep risk assessment and trend tracking across infrastructure, code, and third-party integrations.