cso

Audit application code, dependencies, CI/CD pipelines, and LLM systems for exploitable vulnerabilities.

Updated May 22, 2026
One-click install
npx skills add https://github.com/shekerkamma/peopletech-marketplace --skill cso-shekerkamma
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/shekerkamma/peopletech-marketplace/tree/main/plugins/gstack/cso
Command: npx skills add https://github.com/shekerkamma/peopletech-marketplace --skill cso-shekerkamma

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most teams only audit their own application code, missing 80% of the real attack surface: exposed secrets in CI logs, stale API keys in git history, unpatched critical dependencies, misconfigured CI/CD pipelines, and LLM-specific risks like prompt injection and RAG poisoning. This skill cuts through security theater to find the actual unlocked doors in your infrastructure and code, no checkbox scanning.

Core Features & Use Cases

  • Dual audit modes: Run low-noise daily scans with an 8/10 confidence gate to catch only high-severity issues, or deep comprehensive monthly scans with a 2/10 bar to surface every potential risk.
  • Full attack surface coverage: Scans for secrets archaeology, dependency supply chain flaws, CI/CD security gaps, OWASP Top 10 vulnerabilities, STRIDE threat model gaps, LLM/AI security risks, and malicious skill supply chain issues.
  • Actionable reporting: Delivers confidence-rated findings with concrete remediation steps, not just vague warnings. Use case: A startup preparing for a SOC 2 audit can run a daily scan to catch exposed AWS keys in git history and unpatched Log4j dependencies before their assessor arrives.

Quick Start

Use the cso skill to run a full daily security audit of your project to identify high-confidence vulnerabilities across your infrastructure, code, and dependencies.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit to find critical vulnerabilities in my code and CI/CD pipelines?

Run a security audit using the cso skill to identify exploitable vulnerabilities across application code, dependencies, and CI/CD pipelines. It delivers confidence-rated findings with actionable remediation plans for identified risks.

Can I detect exposed secrets and stale API keys in my git history before a compliance audit?

Yes, you can detect exposed secrets and stale API keys in git history by running a security audit. This skill performs secrets archaeology to find exposed credentials across your infrastructure before an assessor arrives.

What is the best way to identify LLM-specific security risks like prompt injection and RAG poisoning?

The best way to identify LLM-specific security risks like prompt injection and RAG poisoning is using an infrastructure-first security audit. This skill actively verifies identified AI system risks and provides concrete remediation steps.

Does this vulnerability scanning approach support both daily hygiene checks and deep monthly assessments?

Yes, this vulnerability scanning approach supports dual audit modes. You can run low-noise daily scans with an 8/10 confidence gate for high-severity issues, or deep comprehensive monthly scans with a 2/10 bar to surface every potential risk.

How do I perform a supply chain risk assessment for unpatched critical dependencies?

Perform a supply chain risk assessment by scanning for dependency supply chain flaws. This skill evaluates your infrastructure to identify unpatched critical dependencies and malicious skill supply chain issues with confidence-rated findings.