cso

Audit infrastructure security for secrets, supply chain, CI/CD, and LLM risks.

1|Updated Apr 15, 2026
One-click install
npx skills add https://github.com/tyhuffman7/gstack-hermes --skill cso-tyhuffman7
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/tyhuffman7/gstack-hermes/tree/main/gstack-cso
Command: npx skills add https://github.com/tyhuffman7/gstack-hermes --skill cso-tyhuffman7

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security audits that uncover secrets, supply-chain risk, CI/CD vulnerabilities, and LLM/AI security gaps across your stack. It provides a structured approach to verify controls, model threats, and drive remediation with governance-ready outputs. Two modes exist: daily quick checks and comprehensive monthly deep audits, with trend tracking across runs to demonstrate improvement over time.

Core Features & Use Cases

  • Daily quick checks with an 8/10 confidence gate to surface fresh risks across infrastructure, code, and configurations.
  • Comprehensive monthly deep audits for thorough risk assessment, including dependency supply chain and CI/CD pipeline security.
  • Threat modeling, OWASP coverage, and active verification with remediation guidance and governance reporting.
  • Use cases include pre-release security posture validation, incident postmortems, and ongoing risk-trend analysis for policy compliance.

Quick Start

Run the cso skill to perform a daily security audit and generate a posture report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan infrastructure for exposed secrets and CI/CD vulnerabilities?

Run an infrastructure-first security audit to scan code, configurations, and CI/CD pipelines for exposed secrets and supply chain risks. The daily quick check mode surfaces fresh risks fast using an 8/10 confidence gate.

What is the best way to track security posture trends across monthly audits?

Track security posture trends by running comprehensive monthly deep audits that assess dependency supply chains and LLM/AI gaps. The process verifies controls and generates governance-ready reports demonstrating improvement over time.

How do I perform threat modeling and check OWASP coverage for a pre-release validation?

Perform threat modeling and verify OWASP coverage during a pre-release security posture validation. The audit applies active verification to identify risks and provides remediation guidance for closing gaps.

Can I use automated auditing for incident postmortems and compliance risk analysis?

Yes, use automated auditing for incident postmortems and ongoing risk-trend analysis for policy compliance. It evaluates vendor ecosystems and LLM security gaps, producing governance-ready outputs for postmortem reviews.

Does the security audit cover LLM and AI security gaps in my stack?

Yes, the security audit covers LLM and AI security gaps across your stack. It scans infrastructure, code, and vendor ecosystems to identify supply-chain risks and model threats specific to AI implementations.

When should I run a daily quick check instead of a comprehensive deep audit?

Run a daily quick check to rapidly surface fresh risks across configurations with an 8/10 confidence gate. Run a comprehensive monthly deep audit for thorough risk assessment across dependency supply chains and CI/CD pipelines.