What problem does it solve?
Most teams only audit their own application code, missing 80% of the real attack surface: exposed secrets in CI logs, stale API keys in git history, unpatched critical dependencies, misconfigured CI/CD pipelines, and LLM-specific risks like prompt injection and RAG poisoning. This skill cuts through security theater to find the actual unlocked doors in your infrastructure and code, no checkbox scanning.
Core Features & Use Cases
- Dual audit modes: Run low-noise daily scans with an 8/10 confidence gate to catch only high-severity issues, or deep comprehensive monthly scans with a 2/10 bar to surface every potential risk.
- Full attack surface coverage: Scans for secrets archaeology, dependency supply chain flaws, CI/CD security gaps, OWASP Top 10 vulnerabilities, STRIDE threat model gaps, LLM/AI security risks, and malicious skill supply chain issues.
- Actionable reporting: Delivers confidence-rated findings with concrete remediation steps, not just vague warnings. Use case: A startup preparing for a SOC 2 audit can run a daily scan to catch exposed AWS keys in git history and unpatched Log4j dependencies before their assessor arrives.
Quick Start
Use the cso skill to run a full daily security audit of your project to identify high-confidence vulnerabilities across your infrastructure, code, and dependencies.