cso

Identify and remediate security risks across code, dependencies, CI/CD pipelines, and AI workflows.

Updated Apr 12, 2026
One-click install
npx skills add https://github.com/singhianand23045/GarryTan --skill cso-singhianand23045
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/singhianand23045/GarryTan/tree/main/cso
Command: npx skills add https://github.com/singhianand23045/GarryTan --skill cso-singhianand23045

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security posture across code, dependencies, CI/CD pipelines, and AI workflows by performing infrastructure-first audits and active verification to reduce risk.

Core Features & Use Cases

  • Secrets archaeology, dependency-supply-chain scanning, and exposure assessment.
  • CI/CD security checks, LLM/AI security auditing, and skill-supply-chain scanning.
  • Active verification with trend tracking across audit runs and proactive remediation.

Quick Start

Run /cso to start a daily security posture audit across your project and its supply chain.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an infrastructure-first security audit for software development?

An infrastructure-first security audit identifies and remediates risks across code, dependencies, CI/CD pipelines, and AI workflows. It analyzes secrets exposure, dependency provenance, and LLM prompts to reduce overall risk through active verification.

How do I perform STRIDE threat modeling and OWASP Top 10 checks across my project?

Run a comprehensive security scan to evaluate your project against OWASP Top 10 and STRIDE threat modeling frameworks. This process checks secrets exposure, dependency supply chains, and CI/CD pipeline configurations to identify actionable risks.

Can I check my CI/CD pipeline and dependency supply chain for secrets exposure?

Yes, you can perform secrets archaeology and dependency-supply-chain scanning to assess exposure. The audit actively verifies your CI/CD pipelines and dependency provenance to pinpoint and remediate hidden security vulnerabilities.

What is the best way to audit LLM prompts and AI workflows for security vulnerabilities?

The best way is executing a targeted LLM and AI security auditing process. This evaluates your AI workflows and LLM prompts for potential vulnerabilities, integrating the findings into your broader security posture and active verification reports.

How do I track security posture trends and remediation progress over time?

You can track security posture trends by running daily posture checks and monthly comprehensive scans. The audit provides active verification with trend tracking across runs, enabling proactive remediation of identified risks over time.