cso

Audit security posture across infrastructure, dependencies, and CI/CD pipelines.

1|Updated Mar 28, 2026
One-click install
npx skills add https://github.com/shhubbh/flowstate --skill cso-shhubbh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/shhubbh/flowstate/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/shhubbh/flowstate --skill cso-shhubbh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams often lack a complete view of risk spanning infrastructure, CI/CD pipelines, dependencies, and AI/LLM interactions. This skill provides an infrastructure-first security audit that finds secrets archaeology, supply-chain risks, threat modeling, and active verification to close gaps before exploitation.

Core Features & Use Cases

  • Infra-first audit across CI/CD, secrets archaeology, supply-chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Daily zero-noise gate with an 8/10 confidence threshold and a comprehensive monthly scan to track trends over time.
  • Active verification and governance by connecting findings to remediation plans and stakeholder communication.

Quick Start

Run a daily infrastructure- and code-focused security audit to surface high-priority risks.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit CI/CD pipelines and infrastructure for security risks?

A security posture audit surfaces hidden risks across infrastructure, dependencies, and CI/CD pipelines by enforcing OWASP Top 10, STRIDE threat modeling, and secrets archaeology to drive remediation.

How does STRIDE threat modeling work during a supply-chain scan?

STRIDE threat modeling during a supply-chain scan categorizes security risks across infrastructure and dependencies, using active verification to validate vulnerabilities before they can be exploited.

Can I run daily security audits without generating alert fatigue?

Daily security audits can run without alert fatigue by enforcing a zero-noise gate with an 8/10 confidence threshold, surfacing only high-priority risks for immediate remediation.

What is the best way to track security posture trends over time?

The best way to track security posture trends is by running comprehensive monthly scans alongside daily zero-noise checks, allowing you to monitor infrastructure and dependency risk reduction over time.

Does this security audit include secrets archaeology and active verification?

Yes, the security audit includes secrets archaeology to uncover hidden credentials and active verification to confirm vulnerabilities, directly connecting findings to remediation plans and stakeholder communication.

When do I need an infrastructure-first security audit?

You need an infrastructure-first security audit when your security teams lack a complete view of risk spanning CI/CD pipelines, dependencies, and infrastructure, requiring active verification to close gaps before exploitation.