cso

Audit infrastructure security with OWASP and STRIDE threat modeling.

Updated May 11, 2026
One-click install
npx skills add https://github.com/wodeh/gstack-kimi --skill cso-wodeh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/wodeh/gstack-kimi/tree/main/cso
Command: npx skills add https://github.com/wodeh/gstack-kimi --skill cso-wodeh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides infrastructure-first security auditing to uncover secrets, verify dependency supply chains, secure CI/CD pipelines, and guard AI/LLM integrations, while applying OWASP Top 10 and STRIDE threat modeling with active verification.

Core Features & Use Cases

  • Infrastructure-first security audit framework with two modes: daily zero-noise checks and monthly deep scans.
  • Comprehensive coverage including secrets archaeology, dependency supply chain, CI/CD security, LLM/AI security, and skill supply chain scanning.
  • Use cases include security governance reviews, threat modeling sessions, and ongoing risk assessment across large codebases and deployment pipelines.

Quick Start

Run a daily zero-noise security audit and, when needed, a monthly deep scan, then review and remediate findings.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit for CI/CD pipelines and dependencies?

An infrastructure security audit validates CI/CD pipeline security, verifies dependency supply chains, and performs secrets archaeology. It applies OWASP Top 10 and STRIDE threat modeling to uncover vulnerabilities across projects and deployment environments.

What is secrets archaeology and how does it secure software delivery?

Secrets archaeology is the process of excavating hardcoded credentials and sensitive tokens within codebases. It secures software delivery by identifying exposed secrets across projects and environments before they can be exploited in deployment pipelines.

How do I apply STRIDE threat modeling and OWASP reviews to a large codebase?

STRIDE threat modeling and OWASP reviews are applied through structured security governance checks. The process identifies and categorizes risks across large codebases, verifying infrastructure and LLM/AI integrations to ensure comprehensive risk assessment and secure software delivery.

Can I run daily security checks without generating excessive alert noise?

Yes, you can run daily zero-noise security checks designed specifically to avoid excessive alert noise. These checks perform rapid vulnerability assessments, while monthly deep scans are available for comprehensive security governance reviews and deeper risk analysis.

Does infrastructure security auditing cover LLM and AI safety?

Yes, infrastructure security auditing explicitly covers LLM and AI safety. It includes scanning skill supply chains and guarding AI integrations to identify vulnerabilities, ensuring that machine learning components meet governance and verification standards.

What is the best way to validate a dependency supply chain for vulnerabilities?

The best way to validate a dependency supply chain is through active verification during a security audit. This framework validates dependencies, scans skill supply chains, and cross-references findings against threat models to ensure the integrity of software delivery.