cso

Identify security posture risks across code, dependencies, CI/CD pipelines, and infrastructure.

1|Updated Mar 23, 2026
One-click install
npx skills add https://github.com/txema-puch/drone-ai-saturdays --skill cso-txema-puch
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/txema-puch/drone-ai-saturdays/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/txema-puch/drone-ai-saturdays --skill cso-txema-puch

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Chief Security Officer audit skill provides an infrastructure-first security posture assessment across code, dependencies, CI/CD pipelines, and operational environments. It helps identify weak security controls, misconfigurations, and supply-chain risks before they can be exploited, enabling teams to prioritize remediation.

Core Features & Use Cases

  • Multi-phase security audit: Executes a comprehensive review across design, code, dependencies, pipelines, and supply-chain with both daily and monthly deep-scan modes.
  • Threat modeling & OWASP alignment: Applies STRIDE, threat modeling practices, and OWASP Top 10 coverage to uncover high-risk areas.
  • Actionable security posture report: Produces structured findings and remediation plans suitable for executive reviews and engineering backlogs.

Quick Start

Invoke the /cso audit to run a daily security posture assessment against the repository and deployment pipelines.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my code repository for security posture risks and supply-chain vulnerabilities?

A security posture audit assesses code, dependencies, CI/CD pipelines, and infrastructure to identify misconfigurations and supply-chain risks. It applies STRIDE threat modeling and OWASP Top 10 alignment to uncover high-risk areas and produce structured remediation plans.

What is the best way to perform an OWASP-aligned threat model on deployment environments?

The best way to perform an OWASP-aligned threat model is to apply STRIDE practices across your deployment environments to uncover high-risk areas. This process produces structured security posture findings and staged remediation plans suitable for engineering backlogs.

Can I run a daily security check on my CI/CD pipelines for sensitive data exposure?

Yes, you can execute daily quick checks against CI/CD pipelines to identify sensitive data exposure, secrets, and supply-chain risks. These daily security posture assessments provide rapid feedback compared to more comprehensive monthly deep audits.

Does a security posture audit generate remediation plans for executive reviews?

Yes, a security posture audit generates actionable reports containing structured findings and staged remediation plans. These reports are designed to be suitable for both executive reviews and integration into engineering backlogs for prioritized fixes.

When should I run a deep security audit instead of a daily quick check?

You should run a deep security audit monthly to perform a comprehensive review across design, code, dependencies, pipelines, and supply-chain. Daily quick checks are better suited for rapid security posture assessments against active repositories and deployment pipelines.