cso

Audit code, dependencies, CI/CD pipelines, and AI interactions for security gaps.

1|Updated May 6, 2026
One-click install
npx skills add https://github.com/yckkkk/reo --skill cso-yckkkk
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/yckkkk/reo/tree/main/.agents/skills/cso
Command: npx skills add https://github.com/yckkkk/reo --skill cso-yckkkk

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode provides a structured, infrastructure-first security audit that uncovers secrets, dependency risks, CI/CD weaknesses, and AI/LLM-related security gaps across a project.

Core Features & Use Cases

  • Infrastructure-first security audits (secrets archaeology, dependency supply chain, CI/CD pipeline security)
  • LLM/AI security and skill supply chain scanning
  • OWASP Top 10, STRIDE threat modeling, and active verification
  • Daily quick checks and comprehensive monthly deep scans with trend tracking

Quick Start

Run the cso skill to start a daily security audit and view the latest findings.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my CI/CD pipeline and dependencies?

Perform a security audit by running structured scans across code, dependencies, and CI/CD pipelines. The audit identifies secrets, supply chain risks, and pipeline weaknesses, then outputs a prioritized remediation plan for your infrastructure.

What is secrets archaeology and how does it secure my codebase?

Secrets archaeology is the process of scanning your codebase to uncover hidden or hardcoded credentials. It secures your project by identifying these exposed secrets during daily quick checks or monthly deep scans, enabling immediate remediation.

Can I use threat modeling and OWASP Top 10 checks for LLM and AI security?

Yes, you can use threat modeling and OWASP Top 10 checks for LLM and AI security. The audit actively verifies AI interactions and skill supply chains, applying specific risk gates to ensure your AI integrations remain secure.

What is the difference between daily quick checks and monthly deep scans?

Daily quick checks enforce an 8/10 risk gate for immediate security posture gaps, while monthly deep scans use a 2/10 gate for comprehensive analysis across secrets, dependencies, and CI/CD with trend tracking over time.

What's the best way to remediate infrastructure security risks identified during an audit?

The best way to remediate infrastructure security risks is to follow the prioritized findings in the generated remediation plan. This plan structures fixes based on the severity of secrets, dependency, and CI/CD weaknesses found during the audit.