What problem does it solve? Security reviews are easy to skip and hard to do consistently. This Skill runs a structured Chief Security Officer audit over your repository, covering secrets exposure, dependency supply chain risks, CI/CD pipeline weaknesses, LLM/AI attack surface, and the OWASP Top 10, so vulnerabilities surface before attackers find them. ## Core Features & Use Cases - Infrastructure-first audit: secrets archaeology, dependency supply chain scanning, CI/CD pipeline security, and skill supply chain scanning. - Threat modeling and verification: STRIDE threat modeling, OWASP Top 10 review, and active verification of findings rather than speculative reports. - Two audit modes: a daily zero-noise mode gated at 8/10 confidence, and a comprehensive monthly deep scan with a 2/10 reporting bar, plus trend tracking across audit runs. - Use Case: Before shipping a release, ask for a security audit of the current branch. The Skill scans for leaked secrets, vulnerable dependencies, and misconfigured pipelines, then reports only high-confidence findings with concrete fixes. ## Quick Start Ask the assistant to run a security audit of this repository and report high-confidence vulnerabilities with fixes.