cso

Identify and remediate security posture gaps across dependencies, secrets, CI/CD pipelines, and AI risk surfaces.

2|1|Updated Mar 5, 2026
One-click install
npx skills add https://github.com/vnmoorthy/Skylog --skill cso-vnmoorthy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/vnmoorthy/Skylog/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/vnmoorthy/Skylog --skill cso-vnmoorthy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infra-first security audits that surface and remediate infrastructure, supply chain, and AI risk across the software stack to reduce exposure and improve governance.

Core Features & Use Cases

  • Secrets archaeology and dependency-supply-chain scanning to surface hidden credentials, leaked tokens, and stale components.
  • CI/CD pipeline security assessment, build-time risk, and configuration hardening guidance.
  • LLM/AI safety auditing and skill-supply-chain verification to prevent prompt leakage and model risk.
  • OWASP Top 10 coverage, STRIDE threat modeling, and active verification across the lifecycle.
  • Two modes: daily zero-noise checks and comprehensive monthly audits with trend tracking.

Quick Start

Invoke the skill with /cso to start a baseline security posture audit across dependencies, secrets, and CI/CD risk.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit across CI/CD pipelines and dependencies?

A security audit scans dependencies, secrets, and CI/CD pipeline configurations to surface hidden credentials, leaked tokens, and build-time risks. It provides clear configuration hardening guidance and actionable remediation steps to reduce exposure.

What is STRIDE threat modeling and when do I need it for application security?

STRIDE threat modeling identifies security threats across the software lifecycle using structured categories. You need it during pentest reviews and security audits to actively verify OWASP Top 10 coverage and remediate infrastructure posture gaps.

How do I check for leaked secrets and vulnerable components in my software supply chain?

You check for leaked secrets and vulnerable components through secrets archaeology and dependency-supply-chain scanning. This process surfaces hidden credentials, leaked tokens, and stale components to reduce your overall software supply chain exposure.

Can I audit LLM and AI safety risks alongside traditional infrastructure security?

Yes, you can audit LLM and AI safety risks alongside traditional infrastructure. The process evaluates AI risk surfaces and skill-supply-chain verification to prevent prompt leakage and model risk during your overall security posture assessment.

Does this approach support daily lightweight security checks or only monthly deep scans?

This approach supports both daily lightweight checks and comprehensive monthly deep scans. The two operating modes provide zero-noise daily verification and monthly trend tracking to meet active verification requirements across the lifecycle.

What is the best way to harden CI/CD pipeline configuration against build-time threats?

The best way to harden CI/CD pipelines is to assess build-time risks and configuration gaps during an infra-first security audit. This identifies exposure points and provides specific hardening guidance to improve governance and reduce attack surfaces.