cso

Audits infrastructure and applications for vulnerabilities across dependencies, CI/CD pipelines, and LLM/AI components using OWASP Top 10 and STRIDE threat modeling.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/Santiagoisper/BOPE_VERSION_DEFINITIVA --skill cso-santiagoisper
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Santiagoisper/BOPE_VERSION_DEFINITIVA/tree/main/.agents/skills/gstack/cso
Command: npx skills add https://github.com/Santiagoisper/BOPE_VERSION_DEFINITIVA --skill cso-santiagoisper

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Read, Grep, Glob, Write, Agent, WebSearch, AskUserQuestion, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a robust security audit, identifying vulnerabilities and suggesting remediation plans, ensuring the integrity and security of your infrastructure and applications.

Core Features & Use Cases

  • Infrastructure-first Security Audit: Focuses on secrets archaeology, dependency supply chain, CI/CD pipeline security, and LLM/AI security.
  • Skill Supply Chain Scanning: Detects security flaws and malicious components in AI agent skills.
  • OWASP Top 10, STRIDE Threat Modeling: Incorporates industry-standard security assessments.
  • Active Verification: Ensures the effectiveness of security measures.
  • Use Case: For organizations looking to conduct a thorough security audit of their infrastructure and applications, identifying potential vulnerabilities and ensuring compliance with security standards.

Quick Start

Run the cso skill to initiate a full security audit of your system.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a comprehensive security audit for infrastructure and LLM components?

A comprehensive security audit checks for vulnerabilities in dependencies, CI/CD pipelines, and LLM/AI components using OWASP Top 10 and STRIDE threat modeling to identify flaws and suggest remediation plans.

What is included in an LLM security and dependency scanning assessment?

An LLM security and dependency scanning assessment includes secrets archaeology, dependency supply chain analysis, CI/CD pipeline security checks, and detection of malicious components in AI agent skills.

Does this security audit support active verification for CI/CD pipeline security?

Yes, the security audit supports active verification to ensure the effectiveness of security measures within your CI/CD pipeline security and infrastructure components.

Can I use STRIDE threat modeling and OWASP Top 10 for vulnerability assessments?

Yes, you can use this approach to incorporate industry-standard OWASP Top 10 and STRIDE threat modeling methodologies into your vulnerability assessments for robust remediation planning.

What is the best way to detect malicious components in AI agent skills?

The best way to detect malicious components in AI agent skills is through dedicated skill supply chain scanning, which identifies security flaws and malicious components within AI infrastructures.