cso

Automate infrastructure-first security audits and threat modeling across software projects.

1|Updated Apr 26, 2026
One-click install
npx skills add https://github.com/tblakex01/conductor-playground --skill cso-tblakex01
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/tblakex01/conductor-playground/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/tblakex01/conductor-playground --skill cso-tblakex01

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams need scalable, repeatable audits across codebases and deployments to identify secrets, supply chain risks, and misconfigurations. This Skill provides infrastructure-first security auditing, threat modeling, and active verification at both daily and monthly cadences.

Core Features & Use Cases

  • Daily zero-noise security checks that flag high-confidence findings and propose remediation.
  • Comprehensive monthly deep-dive audits covering secrets archaeology, dependency-supply-review, CI/CD security, LLM/AI risk, OWASP Top 10, and STRIDE threat modeling.
  • Active verification and risk-scoring with plan-mode gated workflows to guide remediation for engineering teams.

Quick Start

Say "security audit" to initiate a lightweight CSO mode audit and load the operational instructions from SKILL.md into context.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits and threat modeling across my software projects?

Automating security audits and threat modeling involves running infrastructure-first scans that evaluate secrets, supply chain risks, and misconfigurations. This approach provides structured daily zero-noise checks and monthly deep-dive reviews using plan-mode gated workflows.

What is the best way to detect hardcoded secrets and dependency supply chain risks in a codebase?

Detecting hardcoded secrets and dependency supply chain risks requires dedicated archaeology scans within a broader security audit. These scans identify high-confidence vulnerabilities and misconfigurations, proposing actionable remediation steps to harden the deployment pipeline.

Can I run lightweight daily security checks without generating excessive false positives?

Daily security checks can be run with zero-noise by flagging only high-confidence findings. This lightweight audit mode focuses on immediate infrastructure risks and provides precise remediation guidance without overwhelming engineering teams with false alerts.

Does this threat modeling approach support LLM and AI security risk assessments?

Threat modeling and security audits explicitly support LLM and AI security risk assessments. Monthly deep-dive reviews evaluate AI-specific vulnerabilities alongside OWASP Top 10 and STRIDE methodologies to ensure comprehensive coverage of emerging threats.

How do I harden CI/CD pipelines and perform active verification of security vulnerabilities?

Hardening CI/CD pipelines requires targeted security audits that identify misconfigurations and enforce active verification. Risk-scoring and plan-mode gated workflows then guide engineering teams through structured remediation to secure the deployment process.