cso

Audit infrastructure security posture across secrets, supply chain, CI/CD, and AI/LLM.

Updated Feb 27, 2026
One-click install
npx skills add https://github.com/zhifengzhang-sz/divine-book --skill cso-zhifengzhang-sz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/zhifengzhang-sz/divine-book/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/zhifengzhang-sz/divine-book --skill cso-zhifengzhang-sz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Infrastructure-first security posture auditing to uncover secrets, supply-chain risks, CI/CD vulnerabilities, and AI/LLM security gaps.

Core Features & Use Cases

  • Infrastructure-first security audit covering secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, supply chain scanning, OWASP Top 10, STRIDE threat modeling, and active verification.
  • Daily and comprehensive scan modes with defined confidence gates and trend tracking across runs.
  • Use cases: security posture assessment for large modern deployments, risk prioritization, and remediation planning across complex environments.

Quick Start

Run the daily CSO audit to surface security gaps in infrastructure, CI/CD, and supply chains.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my infrastructure to uncover secrets and CI/CD vulnerabilities?

You can run a daily security posture audit to surface infrastructure gaps, CI/CD pipeline vulnerabilities, and supply chain risks. It uses defined confidence gates and trend tracking across runs for continuous security monitoring.

What is STRIDE threat modeling and how does it apply to infrastructure security?

STRIDE threat modeling is a framework for identifying security threats like spoofing and elevation of privilege. This Skill applies STRIDE alongside OWASP Top 10 during active verification across projects to identify and prioritize infrastructure security risks.

Does this security audit cover AI and LLM security vulnerabilities?

Yes, the security audit covers AI and LLM security gaps alongside traditional infrastructure. It actively verifies supply chain dependencies and CI/CD pipelines to ensure machine learning models and integrations do not introduce unmitigated risks.

Can I use this for comprehensive security posture assessment on large modern deployments?

Yes, this Skill is designed for security posture assessment of large modern deployments. It supports both daily and comprehensive scan modes, applying active verification to prioritize risks and generate remediation planning across complex environments.

How do I identify dependency supply chain risks in my project?

To identify dependency supply chain risks, the audit scans your project dependencies for known vulnerabilities and malicious packages. It implements predefined tooling constraints and active verification to surface supply chain security gaps within the posture report.