What problem does it solve?
Security teams often struggle to get a complete, actionable view of risk across infrastructure, CI/CD pipelines, and AI systems. This Skill provides an infrastructure-first security audit that surfaces secrets archaeology, supply-chain risks, and threat models in a repeatable workflow.
Core Features & Use Cases
- Infrastructure-focused audits that map trusted boundaries and identify exposed configurations.
- Dependency supply chain scanning for known CVEs and risky transitive dependencies.
- CI/CD security checks to prevent secret leakage, insecure workflows, and pipeline misconfigurations.
- Threat modeling and OWASP coverage using STRIDE and Top 10 mappings to guide remediation.
- Two-mode operation for daily zero-noise checks and comprehensive monthly scans with trend tracking.
Quick Start
Invoke the cso audit in daily mode to start an automated security posture assessment.