cso

Audit infrastructure, applications, and development processes for security vulnerabilities.

Updated Apr 8, 2026
One-click install
npx skills add https://github.com/sadie100/claude-dotfiles --skill cso-sadie100
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/sadie100/claude-dotfiles/tree/main/skills/cso
Command: npx skills add https://github.com/sadie100/claude-dotfiles --skill cso-sadie100

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Grep, Git, npm, pip, cargo, go, mcp, OpenAI_API_KEY, ANTHROPIC_API_KEY, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive security audit and threat modeling tool, helping to identify and mitigate vulnerabilities in infrastructure, applications, and processes.

Core Features & Use Cases

  • Security Audit: Conduct thorough security audits including secrets archaeology, dependency supply chain analysis, CI/CD pipeline security, infrastructure shadow surface, webhook & integration audit, LLM/AI security, and skill supply chain scanning.
  • Threat Modeling: Evaluate components for spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.
  • Data Classification: Classify all data handled by the application into restricted, confidential, internal, and public categories.
  • Use Case: When preparing for a security audit or assessing the security posture of a new project, use this Skill to automatically scan and report on potential vulnerabilities.

Quick Start

Run the cso skill to initiate a security audit on your project.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit to detect exposed secrets and vulnerable dependencies in my project?

A comprehensive security audit detects exposed secrets and vulnerable dependencies by utilizing Bash, Grep, Git, and package managers like npm, pip, cargo, and go to scan infrastructure and applications. It identifies vulnerabilities across your codebase, CI/CD pipelines, and supply chain.

What is threat modeling and how does it evaluate application security?

Threat modeling evaluates application security by assessing components for spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. It systematically classifies data into restricted, confidential, internal, and public categories to mitigate vulnerabilities.

Can I scan my CI/CD pipeline security and infrastructure shadow surface using Bash and Grep?

Yes, you can scan CI/CD pipeline security and infrastructure shadow surfaces using Bash and Grep. The audit process leverages these tools alongside Git and package managers to identify vulnerabilities, webhook integrations, and exposed secrets within your development infrastructure.

Does this security audit support LLM and AI security assessment?

Yes, the security audit supports LLM and AI security assessment, along with skill supply chain scanning. It utilizes OpenAI and Anthropic API integrations to identify vulnerabilities specific to artificial intelligence infrastructure and development processes.

What's the best way to automate vulnerability assessment for a new development project?

The best way to automate vulnerability assessment for a new project is running a comprehensive security audit that scans secrets, dependencies, and CI/CD pipelines. It uses Bash, Grep, and package manager tools to automatically identify and report potential vulnerabilities.

Do I need API keys to conduct a webhook and integration audit?

Yes, you need OpenAI and Anthropic API keys to conduct webhook, integration, and LLM security audits. The vulnerability assessment also requires Bash, Grep, Git, and package managers like npm, pip, cargo, and go to scan infrastructure and applications.