What problem does it solve?
Manual security audits are slow, inconsistent, and buried in low-confidence false positives that waste engineering time. This Skill automates end-to-end infrastructure security testing with a confidence gate that only reports high-risk, verified findings for daily use, plus a deep scan mode for monthly comprehensive reviews.
Core Features & Use Cases
- Secrets Archaeology: Scan codebases for exposed API keys, tokens, and credentials across all file types and commit history.
- Supply Chain Security: Audit dependencies for known vulnerabilities, malicious packages, and CI/CD pipeline misconfigurations.
- AI/LLM Security Checks: Identify prompt injection risks, RAG poisoning vulnerabilities, and unsafe tool calling permissions in AI features.
- OWASP & STRIDE Validation: Run automated OWASP Top 10 scans and STRIDE threat modeling for web and cloud infrastructure.
- Active Verification: Test identified vulnerabilities in a safe environment to eliminate false positives before reporting.
- Use Case: A SaaS engineering team can run a daily zero-noise audit before deployments to catch critical issues fast, and a monthly deep scan to meet compliance requirements.
Quick Start
Use the cso skill to run a daily zero-noise security audit of the current project and share only high-confidence findings with the engineering team.