cso

Monitor security posture across infrastructure, code, and third-party risk.

1|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/westn/gstack-pi-port --skill cso-westn
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/westn/gstack-pi-port/tree/main/port/gstack/cso
Command: npx skills add https://github.com/westn/gstack-pi-port --skill cso-westn

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode focuses on infrastructure-first security audits to identify secrets archaeology, supply chain weaknesses, CI/CD pipeline gaps, and AI/LLM security risks, delivering a clear, actionable security posture.

Core Features & Use Cases

  • Infrastructure-first security assessment across the full tech stack, including secrets, dependencies, pipelines, and model safety.
  • Actionable risk reports with prioritized remediation steps and evidence you can verify.
  • Use cases include ongoing security hygiene, compliance readiness, and executive risk reviews across daily and comprehensive scans.

Quick Start

Invoke the cso skill to start the daily audit now.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an infrastructure security audit for secrets and CI/CD pipeline risks?

An infrastructure security audit scans for secrets archaeology, CI/CD pipeline gaps, and supply chain weaknesses to deliver a structured security posture report. It identifies concrete findings and prioritized remediation steps you can actively verify.

What is the difference between a daily security scan and a comprehensive posture audit?

A daily security scan operates in high-speed mode for ongoing security hygiene, while a comprehensive posture audit executes a deep scan. Both output actionable risk reports, but comprehensive mode provides deeper analysis for compliance readiness and executive risk reviews.

Can I assess LLM and AI security risks as part of my overall security posture?

Yes, security posture audits include LLM and AI security risk assessments alongside infrastructure, code, and third-party risk. The audit evaluates model safety and outputs actionable findings with evidence within the structured security posture report.

What's the best way to prepare for compliance readiness using automated threat modeling?

Automated threat modeling and security posture audits generate prioritized remediation steps and evidence for compliance readiness. Running comprehensive scans across your infrastructure, dependencies, and pipelines produces the actionable risk reports required for executive reviews.

Does this security audit cover third-party dependency supply chain scanning?

Yes, dependency supply chain scanning is a core component of the security posture audit. It evaluates third-party risks alongside secrets archaeology and CI/CD pipeline security, outputting concrete findings and remediation plans within the final report.

How do I get actionable remediation steps from a security posture report?

Security posture reports automatically generate prioritized remediation steps and concrete findings based on infrastructure, code, and third-party risk assessments. The report includes a plan for active verification, ensuring you can validate the applied security fixes.