cso

Automate infrastructure-first security audits across CI/CD pipelines and dependencies.

2|Updated May 8, 2026
One-click install
npx skills add https://github.com/xotong/claude-marketplace --skill cso-xotong
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/xotong/claude-marketplace/tree/main/plugins/gstack/skills/cso
Command: npx skills add https://github.com/xotong/claude-marketplace --skill cso-xotong

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security auditing across CI/CD pipelines, secrets archaeology, dependency supply chain checks, and AI/LLM safety governance.

Core Features & Use Cases

  • Comprehensive risk assessment, threat modeling, OWASP-aligned checks, and active verification.
  • Daily lightweight scans and monthly deep audits with trend tracking across runs.
  • Use Case: For an ongoing project, trigger a CSO mode audit to surface critical vulnerabilities and remediation steps.

Quick Start

Run the CSO mode audit on the current project and generate an actionable risk report.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits across CI/CD pipelines and supply chains?

You can automate infrastructure-first security auditing across CI/CD pipelines using a two-mode workflow of daily lightweight scans and monthly deep audits. This surfaces critical vulnerabilities and tracks risk trends across large software projects.

What is threat modeling and OWASP-aligned assessment for large software projects?

Threat modeling and OWASP-aligned assessments systematically identify and evaluate infrastructure security risks. This Skill applies active verification to detect vulnerabilities and generates actionable risk reports with remediation steps for ongoing projects.

Can I perform daily security scans and monthly deep audits with trend tracking?

Yes, this Skill implements a two-mode workflow supporting daily lightweight scans and monthly deep audits with trend tracking across runs. This ensures continuous security gating while monitoring risk management improvements over time.

Does infrastructure-first security auditing work for AI and LLM safety governance?

Infrastructure-first security auditing applies to AI and LLM safety governance by implementing active verification and security gating across CI/CD pipelines. This ensures large software projects meet safety requirements during ongoing dependency checks.

What is the best way to conduct secrets archaeology and dependency supply chain checks?

The best way to conduct secrets archaeology and dependency supply chain checks is through automated infrastructure-first security auditing. This approach integrates CI/CD security and risk management to surface vulnerabilities and provide actionable remediation steps.

When do I need to trigger a security review for an ongoing project?

You need to trigger a security review for an ongoing project to surface critical vulnerabilities and remediation steps. Running a mode audit generates an actionable risk report for comprehensive risk assessment and threat modeling.