cso

Automate infrastructure-first security audits with secrets archaeology and dependency checks.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/scanbott/claude-skills --skill cso-scanbott
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/scanbott/claude-skills/tree/main/gstack/cso
Command: npx skills add https://github.com/scanbott/claude-skills --skill cso-scanbott

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure teams struggle with securing complex stacks and keeping risk visibility across pipelines, vendors, and AI components. This Skill standardizes and automates security audits from secrets archaeology to supply chain verification.

Core Features & Use Cases

  • Secrets archaeology and dependency supply chain checks
  • CI/CD and pipeline security validations
  • OWASP Top 10 and STRIDE threat modeling with active verification
  • Daily quick checks and monthly deep audits with trend tracking Use cases include security reviews for org risk, threat model exercises, and ongoing security hygiene across dev, test, and prod.

Quick Start

Run a daily security audit with gstack to start the zero-noise, 8/10 confidence gate and track trends across runs.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate infrastructure security audits for CI/CD pipelines?

Automate infrastructure security audits by running standardized checks for secrets archaeology, supply chain dependencies, and CI/CD pipeline security. This Skill enforces safe, auditable outcomes with active verification across your modern stack.

What is the best way to perform secrets archaeology and dependency supply chain checks?

Perform secrets archaeology and dependency supply chain checks by using automated tooling to scan for exposed credentials and validate third-party dependencies. This approach standardizes risk visibility across your infrastructure pipelines.

Can I use OWASP Top 10 and STRIDE threat modeling for ongoing security hygiene?

Yes, you can apply OWASP Top 10 and STRIDE threat modeling for ongoing security hygiene. The Skill supports daily quick checks and monthly deep audits with trend tracking across dev, test, and prod environments.

Does this security audit approach work for AI and LLM risk assessment?

Yes, this security audit approach works for AI and LLM risk assessment. It targets security teams and DevOps workflows by applying active verification to enforce safe, auditable outcomes for modern AI components.

What do I need to run threat modeling and supply chain verification across my stack?

To run threat modeling and supply chain verification, you need tooling for secrets scanning, dependency analysis, and active verification. The Skill applies these tools across daily quick checks and monthly comprehensive audits.