cso

Audit infrastructure for secrets, dependency, CI/CD, and LLM security risks.

Updated Mar 27, 2026
One-click install
npx skills add https://github.com/TobiasPerry/aws-hackathon --skill cso-tobiasperry
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/TobiasPerry/aws-hackathon/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/TobiasPerry/aws-hackathon --skill cso-tobiasperry

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Secrets archaeology, dependency supply chain weaknesses, CI/CD pipeline security gaps, and LLM/AI security risks are identified and mitigated with an infrastructure-first approach, reducing exposure and improving resilience.

Core Features & Use Cases

  • Infrastructure-focused security audit across secrets archaeology, dependency supply chain, CI/CD security, and AI/LLM risk vectors.
  • Threat modeling and OWASP-aligned risk reviews (STRIDE-based).
  • Two-mode operation: daily zero-noise checks and comprehensive monthly deep scans for deeper coverage.

Quick Start

Run a daily CSO audit to begin infrastructure-first security assessment across the project.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my CI/CD pipeline and dependency supply chain?

A security audit identifies CI/CD pipeline gaps and dependency supply chain weaknesses using an infrastructure-first approach. It uncovers exposed secrets and mitigates risks across development, staging, and production environments to improve resilience.

What is secrets archaeology and how does it reduce exposure in enterprise projects?

Secrets archaeology is the process of uncovering hardcoded or leaked credentials within your codebase and pipelines. It reduces exposure by identifying and mitigating these hidden secrets before they can be exploited across your enterprise project infrastructure.

How does STRIDE-based threat modeling work for infrastructure security?

STRIDE-based threat modeling applies an OWASP-aligned risk review to your infrastructure security. It categorizes threats across your development, staging, and production pipelines to support secure posture management and targeted remediation.

Can I run daily security checks without generating alert fatigue?

Yes, you can run daily zero-noise security checks to monitor your infrastructure posture. This operational mode provides rapid, continuous assessment without overwhelming your team with false positives or unnecessary alerts.

What is the best way to assess LLM and AI security risks in my application?

The best way to assess LLM and AI security risks is through a comprehensive infrastructure-focused audit. This process identifies AI risk vectors and applies threat modeling to ensure governance and secure posture management across your pipelines.

When should I run a comprehensive security audit instead of a daily check?

You should run a comprehensive monthly deep scan when you need deeper coverage for enterprise governance and risk assessment. This mode provides extensive threat modeling and vulnerability discovery beyond the scope of daily zero-noise checks.