What problem does it solve?
Security audits are often manual, inconsistent, and noisy, making it hard to catch critical vulnerabilities before they reach production. This skill automates infrastructure-first security audits that cover secrets, dependencies, CI/CD pipelines, and AI/LLM systems, ensuring comprehensive coverage without the noise.
Core Features & Use Cases
- Infrastructure-First Security Audit: Scans for secrets archaeology, dependency supply chain vulnerabilities, CI/CD pipeline security issues, and LLM/AI security risks.
- Compliance Frameworks: Built-in checks for OWASP Top 10 and STRIDE threat modeling with active verification.
- Dual-Mode Operation: Daily zero-noise scans with an 8/10 confidence gate, and monthly comprehensive deep scans with a 2/10 threshold.
- Trend Tracking: Monitors audit results across runs to identify emerging risks and regressions.
Quick Start
Use the cso skill to run a security audit on the current project and generate a threat model report.