cso

Audit infrastructure security posture across secrets, dependencies, CI/CD, and LLM/AI.

10|3|Updated Mar 25, 2026
One-click install
npx skills add https://github.com/olaafrossi/FoamPilot --skill cso-olaafrossi
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/olaafrossi/FoamPilot/tree/main/.claude/skills/cso
Command: npx skills add https://github.com/olaafrossi/FoamPilot --skill cso-olaafrossi

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits that help chief security officers and security teams uncover secrets, insecure dependencies, CI/CD risks, LLM/AI security gaps, and misconfigurations across the tech stack.

Core Features & Use Cases

  • Secrets archaeology and dependency supply chain scanning to prevent credential leaks and tampered dependencies.
  • CI/CD pipeline security checks and LLM/AI security verifications to defend automations.
  • Skill supply chain scanning to reduce risk from tooling and agent integrations.
  • OWASP Top 10 and STRIDE threat modeling to identify practical attack paths.
  • Active verification and trend tracking across audit runs to show improvements over time.

Quick Start

Run a daily audit with /cso to start infrastructure-first security checks.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate infrastructure security audits for secrets and dependency supply chains?

You can automate infrastructure security audits using a multi-phase workflow that scans for leaked secrets and dependency supply chain risks. It leverages tools like Bash, Grep, and Glob to perform automated checks across your tech stack.

What does threat modeling using OWASP Top 10 and STRIDE involve for CI/CD pipelines?

Threat modeling for CI/CD pipelines involves applying OWASP Top 10 and STRIDE methodologies to identify practical attack paths. It actively verifies pipeline security and LLM integrations to defend automations against potential threats.

Can I run daily security posture checks for LLM and AI security gaps?

Yes, you can run daily security posture checks for LLM and AI security gaps. The system supports a daily mode designed to perform targeted checks on secrets archaeology, CI/CD pipeline security, and LLM/AI verifications.

Does this security audit tool work without external dependencies?

Yes, the security audit tool works without external dependencies. It operates autonomously using built-in allowed tools including Bash, Read, Grep, Glob, Write, Agent, WebSearch, and AskUserQuestion to execute its multi-phase workflow.

What is the best way to track security posture improvements across multiple audit runs?

The best way to track security posture improvements is through active verification and trend tracking across audit runs. This approach records improvements over time by comparing daily and comprehensive security scan results.

When should I use comprehensive mode instead of daily mode for security audits?

You should use comprehensive mode for deep security audits during pentest reviews or full threat modeling across organizations. Daily mode is suited for routine checks, while comprehensive mode performs extensive infrastructure-first scanning.