What problem does it solve?
It helps you find and prioritize real security weaknesses by systematically reviewing a project’s attack surface, dependencies, secrets, and threat model.
Core Features & Use Cases
- OWASP-guided vulnerability review: Checks each OWASP Top 10 category with confidence and exploitability filtering.
- STRIDE threat modeling: Produces a structured threat model across major components and trust boundaries.
- Secrets and supply-chain archaeology: Searches for exposed credentials and evaluates dependency vulnerability risk.
- False-positive filtering: Discards low-signal items using explicit rules to reduce noise.
- Prioritized findings report: Outputs CRITICAL/HIGH/MEDIUM/LOW with rationale and where to fix.
Quick Start
Ask the CSO skill to run a daily security audit of the entire repository by providing the project path or leaving the default to scan everything.