cso

Automate Chief Security Officer-style audits of infrastructure, CI/CD, and supply chains.

Updated Apr 7, 2026
One-click install
npx skills add https://github.com/zz8011/harnesstest --skill cso-zz8011
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/zz8011/harnesstest/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/zz8011/harnesstest --skill cso-zz8011

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer level audits that reveal infrastructure, supply chain, and AI security gaps, helping teams reduce risk across CI/CD pipelines and deployed systems.

Core Features & Use Cases

  • Infrastructure-first security audit: secrets archaeology, dependency supply chain checks, CI/CD pipeline hardening, LLM/AI safety verification, and skill-supply-chain scanning.
  • Threat modeling & compliance: OWASP Top 10 coverage, STRIDE threat modeling, and active verification workflows to enforce policy.
  • Modes & governance: daily zero-noise gating (8/10) and comprehensive deep scans with trend tracking across runs.

Quick Start

Invoke the cso skill with its default daily mode to start an infrastructure-first security audit.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a security posture audit for cloud infrastructure and CI/CD pipelines?

Automating a security posture audit requires scanning infrastructure, secrets, and CI/CD pipelines. This skill executes CSO-grade reviews covering supply chain risk, LLM safety, and dependency checks to enforce governance workflows across cloud environments.

What is secrets archaeology and how does it secure my deployment pipeline?

Secrets archaeology is the process of uncovering hidden credentials within codebases and deployment environments. This skill automates this discovery alongside CI/CD pipeline hardening to actively verify and enforce security policies across your infrastructure.

How do I perform threat modeling and OWASP Top 10 coverage checks for my applications?

Threat modeling and OWASP Top 10 coverage checks are performed by applying STRIDE methodologies to identify security gaps. This skill automates active verification workflows to enforce compliance and map remediation workflows across your deployed systems.

Can I use this security audit tool for daily zero-noise gating in my development workflow?

Yes, this security audit tool supports daily zero-noise gating to prevent build interruptions. It operates in a default daily mode scoring 8/10 to provide rapid infrastructure-first checks, alongside comprehensive deep scans with trend tracking across runs.

Does this approach cover LLM security and AI safety verification for third-party dependencies?

Yes, this approach covers LLM security and AI safety verification as part of its core audit phases. It performs skill-supply-chain scanning to identify risk across third-party dependencies, enforcing governance and remediation workflows for AI safety.

What is the best way to conduct a risk-based security review across cloud environments?

The best way to conduct a risk-based security review is using an automated CSO-grade audit. This skill applies structured threat modeling and active verification to assess supply chain risk, CI/CD security, and infrastructure vulnerabilities across cloud environments.