cso

Audit infrastructure and applications for vulnerabilities and OWASP compliance.

1|Updated May 12, 2026
One-click install
npx skills add https://github.com/sobhanashine/nazarato --skill cso-sobhanashine
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/sobhanashine/nazarato/tree/main/.claude/skills/cso
Command: npx skills add https://github.com/sobhanashine/nazarato --skill cso-sobhanashine

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Read, Grep, Glob, Write, Agent, WebSearch, AskUserQuestion, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill enables you to perform regular security audits, scan for vulnerabilities, and conduct OWASP reviews, ensuring your infrastructure remains secure and compliant.

Core Features & Use Cases

  • Security Audits: Regular audits for secrets archaeology, dependency supply chain, CI/CD pipeline, and LLM/AI security.
  • Vulnerability Scanning: Scan for potential vulnerabilities in your systems.
  • OWASP Reviews: Conduct reviews based on the OWASP Top 10.
  • Trend Tracking: Monitor and track trends across audit runs.
  • Use Case: Use this Skill when you need to ensure the security of your infrastructure and applications.

Quick Start

Use the cso skill to perform a security audit on your infrastructure.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my infrastructure?

This Skill performs security audits by scanning your infrastructure and applications for vulnerabilities. It conducts regular checks, threat modeling, and OWASP reviews to ensure your systems remain secure.

What is the best way to scan for OWASP Top 10 vulnerabilities?

The best way to review OWASP Top 10 vulnerabilities is to conduct automated reviews using this Skill. It applies OWASP standards to scan your applications and identify potential security weaknesses.

Can I use this to find exposed secrets in my CI/CD pipeline?

Yes, you can use this to find exposed secrets in your CI/CD pipeline. The security audits include secrets archaeology, dependency supply chain analysis, and CI/CD pipeline checks to uncover hidden credentials.

Does this security audit tool support LLM and AI application scanning?

Yes, this security audit tool supports LLM and AI application scanning. It includes specific audit features designed to evaluate the security posture of your AI integrations and infrastructure.

How do I track security vulnerability trends across multiple audit runs?

You can track security vulnerability trends across multiple audit runs using the built-in trend tracking feature. This monitors and records findings over time, helping you measure your security improvements.

Do I need Bash and WebSearch tools to run infrastructure vulnerability scans?

Yes, you need Bash and WebSearch tools along with Read, Grep, Glob, Write, Agent, and AskUserQuestion to run infrastructure vulnerability scans. These dependencies are required to execute the comprehensive security audits.