cso

Audit infrastructure security across secrets, dependencies, CI/CD, and attack surfaces.

Updated Apr 11, 2026
One-click install
npx skills add https://github.com/Scivor/helm --skill cso-scivor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/Scivor/helm/tree/main/skills/gstack/cso
Command: npx skills add https://github.com/Scivor/helm --skill cso-scivor

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security auditing that unearths secrets, supply-chain risks, misconfigurations, and risky integrations across code, CI/CD, and operations.

Core Features & Use Cases

  • Threat modeling with OWASP Top 10 and STRIDE, plus risk-based verification across code, infra, and pipelines.
  • Secrets archaeology: detect exposed credentials in config files, environment variables, and git history.
  • Dependency supply chain audit: identify vulnerable or unpinned packages, compromised components, and unsafe supply-chain practices.
  • Active verification and remediation guidance with clear risk ratings and traceability for daily and comprehensive scans.

Quick Start

Invoke a daily CSO audit on your project to surface secrets, supply-chain gaps, and misconfigurations.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit to find exposed secrets in config files and git history?

A security audit detects exposed credentials in config files, environment variables, and git history through secrets archaeology. It identifies stale keys and provides concrete risk ratings with actionable remediation guidance for fast resolution.

What is dependency supply chain auditing and how does it identify vulnerable packages?

Dependency supply chain auditing identifies vulnerable or unpinned packages, compromised components, and unsafe supply-chain practices. It targets risky third-party integrations across your infrastructure to prevent supply-chain attacks.

Does this security audit support threat modeling with OWASP Top 10 and STRIDE?

Yes, this security audit performs threat modeling with OWASP Top 10 and STRIDE. It conducts risk-based verification across code, infrastructure, and pipelines to model your attack surface and identify misconfigurations.

Can I use this to check for misconfigurations and insecure container settings in CI/CD?

Yes, you can check for insecure container settings and misconfigurations across CI/CD pipelines. The audit performs infrastructure-first security scanning across environments, identifying misconfigurations and insecure container settings.

What is the best way to automate infrastructure-first security scans for daily and comprehensive modes?

The best way to automate infrastructure-first security scans is implementing a repeatable CSO workflow with daily and comprehensive modes. This surfaces secrets, supply-chain gaps, and misconfigurations with clear risk ratings and traceability.

When do I need LLM and AI security auditing for my operations?

You need LLM and AI security auditing when your infrastructure integrates artificial intelligence components. The audit identifies risky third-party integrations and insecure settings across your LLM and AI operations to prevent attacks.