cso

Run infrastructure-first security audits and generate a Security Posture Report.

Updated Apr 5, 2026
One-click install
npx skills add https://github.com/VertaKhan/cs_gstack --skill cso-vertakhan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/VertaKhan/cs_gstack/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/VertaKhan/cs_gstack --skill cso-vertakhan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode enables automated, infrastructure-first security audits that reveal secrets archaeology, dependency supply chain weaknesses, CI/CD pipeline security gaps, and LLM/AI security risks. It also supports skill supply chain scanning and threat modeling workflows to prevent security incidents before they occur.

Core Features & Use Cases

  • Infrastructure-first security audits covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning.
  • Daily zero-noise audits with an 8/10 confidence gate and monthly comprehensive deep scans to track trends over time.
  • OWASP Top 10 and STRIDE-based threat modeling, active verification, and remediation planning across the codebase and deployment.

Quick Start

Invoke the /cso command to start a daily security posture audit and switch to comprehensive for a deeper scan.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure-first security audit for secrets and CI/CD pipelines?

An infrastructure-first security audit scans for secrets archaeology, dependency supply chain weaknesses, and CI/CD pipeline gaps. It runs multi-phase workflows including stack detection and attack-surface census to generate a Security Posture Report with actionable remediation steps.

What is the difference between a daily security posture scan and a comprehensive deep scan?

A daily security posture scan enforces an 8/10 confidence gate for zero-noise reporting, while a comprehensive deep scan performs monthly checks to track security trends over time. Both identify risks across secrets, dependencies, and pipelines.

Does this security audit support OWASP Top 10 and STRIDE threat modeling?

Yes, the security audit supports OWASP Top 10 and STRIDE-based threat modeling. It performs active verification and remediation planning across your codebase and deployment to prevent security incidents.

Can I detect LLM and AI security risks using an automated security audit?

Yes, automated security audits detect LLM and AI security risks alongside skill supply chain scanning. This prevents security incidents by revealing vulnerabilities in AI integrations and package dependencies.

What is the best way to identify dependency supply chain weaknesses in my codebase?

The best way to identify dependency supply chain weaknesses is through package-supply scanning during a security audit. This process detects vulnerabilities in your dependency tree and provides concrete remediation steps.

What remediation steps are included in a Security Posture Report?

A Security Posture Report includes concrete, actionable remediation steps based on findings from secrets archaeology, package-supply scanning, and CI/CD checks. It translates audit results into specific security governance actions.