What problem does it solve?
This skill addresses the complexity of maintaining secure infrastructure by automating comprehensive security audits, threat modeling, and supply chain verification, ensuring that security is not a bottleneck but a continuous, integrated process.
Core Features & Use Cases
- Infrastructure-First Auditing: Performs deep scans for secrets, dependency vulnerabilities, and CI/CD pipeline misconfigurations.
- AI/LLM Security: Specifically detects prompt injection vectors, unsanitized LLM outputs, and insecure tool-calling patterns.
- Use Case: Before shipping a new production service, invoke this skill to run a full OWASP Top 10 assessment and STRIDE threat model to identify and remediate critical vulnerabilities before they reach production.
Quick Start
Invoke the cso skill to perform a comprehensive security audit and threat model of the current repository.