cso

Identify and prioritize security risks across infrastructure, dependencies, CI/CD pipelines, and AI security.

Updated Feb 16, 2026
One-click install
npx skills add https://github.com/SeaLion-hub/DICEE --skill cso-sealion-hub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/SeaLion-hub/DICEE/tree/main/.agents/skills/gstack/cso
Command: npx skills add https://github.com/SeaLion-hub/DICEE --skill cso-sealion-hub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams often struggle to get a complete, actionable view of risk across infrastructure, CI/CD pipelines, and AI systems. This Skill provides an infrastructure-first security audit that surfaces secrets archaeology, supply-chain risks, and threat models in a repeatable workflow.

Core Features & Use Cases

  • Infrastructure-focused audits that map trusted boundaries and identify exposed configurations.
  • Dependency supply chain scanning for known CVEs and risky transitive dependencies.
  • CI/CD security checks to prevent secret leakage, insecure workflows, and pipeline misconfigurations.
  • Threat modeling and OWASP coverage using STRIDE and Top 10 mappings to guide remediation.
  • Two-mode operation for daily zero-noise checks and comprehensive monthly scans with trend tracking.

Quick Start

Invoke the cso audit in daily mode to start an automated security posture assessment.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits for infrastructure and CI/CD pipelines?

Automate infrastructure and CI/CD security audits by running structured workflows that map trusted boundaries, identify exposed configurations, and check for pipeline misconfigurations. This enforces reproducible posture reports and automated verification gates for clear risk assessment.

What is the best way to scan dependencies for supply chain risks and known CVEs?

The best way to scan dependencies for supply chain risks is using a focused audit that identifies known CVEs and risky transitive dependencies. This approach provides reproducible tracking and integrates into daily checks or monthly comprehensive scans.

How does threat modeling with STRIDE apply to infrastructure security checks?

Threat modeling with STRIDE applies to infrastructure security by mapping trusted boundaries and exposing configuration risks. It uses OWASP Top 10 mappings to guide remediation and structure the audit workflow for reproducible posture reports.

Can I run a quick daily security check without generating excessive noise?

Yes, you can run a daily zero-noise security check using a specific operational mode. This mode performs automated posture assessments for fast risk clarity, contrasting with comprehensive monthly scans that include trend tracking.

Does CI/CD security scanning prevent secret leakage in workflows?

CI/CD security scanning prevents secret leakage by identifying insecure workflows and pipeline misconfigurations. It enforces automated verification gates across the pipeline to ensure secrets archaeology and exposed configurations are remediated.

When should I use comprehensive monthly scans over daily security checks?

Use comprehensive monthly scans when you need trend tracking and full coverage across infrastructure, dependencies, and AI security. Daily checks provide zero-noise quick assessments, while monthly scans deliver deep threat modeling and supply-chain resilience analysis.