cso

Orchestrate infrastructure-first security audits across code, configurations, and supply chains.

Updated Mar 28, 2026
One-click install
npx skills add https://github.com/steadyfall/fspeek --skill cso-steadyfall
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/steadyfall/fspeek/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/steadyfall/fspeek --skill cso-steadyfall

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode orchestrates infrastructure-first security audits across secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification.

Core Features & Use Cases

  • Security audit orchestration: run systematic checks across code, configurations, and supply chains.
  • Threat modeling & policy checks: apply OWASP, STRIDE, and best-practice controls to identify risk.
  • Active verification & reporting: generate actionable findings with remediation guidance for teams.

Quick Start

Run a CSO security audit on my repository.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my repository?

A security audit orchestrates systematic checks across code, configurations, and dependency supply chains to identify risks. It applies OWASP and STRIDE threat modeling to generate actionable findings with standardized remediation guidance for teams.

Can I use threat modeling for CI/CD pipeline security checks?

Yes, you can use threat modeling for CI/CD pipeline security by applying OWASP Top 10 and STRIDE methodologies. This identifies risks across continuous integration and deployment configurations through policy checks and active verification steps.

Does this security audit cover LLM and AI vulnerability scanning?

Yes, the security audit covers LLM and AI vulnerability scanning. It includes dedicated LLM security checks alongside secrets archaeology and supply chain scanning to identify vulnerabilities in AI-integrated software stacks.

What is the best way to perform secrets archaeology across complex software stacks?

The best way to perform secrets archaeology is through infrastructure-first security audits using configurable scans. This uncovers hidden secrets across complex software stacks and hosted environments while generating auditable evidence for risk assessments.

What frameworks are used for threat modeling and policy checks?

Threat modeling and policy checks use OWASP Top 10 and STRIDE frameworks. These frameworks apply best-practice controls to identify and assess risks across complex software stacks and hosted environments during security reviews.