gs:cso

Audit infrastructure security with secrets archaeology, dependency analysis, and threat modeling.

34|6|Updated Apr 19, 2026
One-click install
npx skills add https://github.com/thanh-abaii/gstack-windows-port --skill gs-cso
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gs:cso
Source: https://github.com/thanh-abaii/gstack-windows-port/tree/main/skills/gstack-cso
Command: npx skills add https://github.com/thanh-abaii/gstack-windows-port --skill gs-cso

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Bash, Read, Grep, Glob, Write, Agent, WebSearch, AskUserQuestion, and includes scripts (resource) and references (resource) components.

What problem does it solve?

The gs:cso skill solves the problem of conducting comprehensive security audits and vulnerability scans, ensuring that your infrastructure is secure and up-to-date with the latest threats.

Core Features & Use Cases

  • Infrastructure Security Audit: Provides detailed analysis for infrastructure security, including secrets archaeology and supply chain dependency scanning.
  • Daily & Monthly Scanning: Offers both daily and comprehensive scanning options, ensuring ongoing monitoring of potential threats.
  • Use Case: When you need to ensure your system is secure against common threats, the gs:cso skill can help identify potential vulnerabilities before they are exploited.

Quick Start

To perform a daily security audit, simply use the command '/gs:cso run security audit'.

Frequently Asked Questions about gs:cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a security audit and threat modeling for my infrastructure?

Conducting a security audit and threat modeling involves performing secrets archaeology, dependency supply chain analysis, and CI/CD pipeline checks. This process uses OWASP Top 10 and STRIDE methodologies to identify and evaluate potential vulnerabilities in your infrastructure.

What is STRIDE threat modeling and when should I use it for vulnerability scanning?

STRIDE threat modeling is a framework used to identify security threats like spoofing, tampering, and denial of service. You should use it during comprehensive vulnerability scanning to systematically uncover and categorize potential risks across your infrastructure and applications.

Can I run daily vulnerability scans and dependency supply chain analysis on Windows 11?

Yes, you can run daily vulnerability scans and dependency supply chain analysis on Windows 11 environments. The scanning process supports regular daily checks and comprehensive monthly audits to ensure ongoing monitoring of potential security threats.

How do I check my CI/CD pipeline security and scan for exposed secrets?

Checking CI/CD pipeline security and scanning for exposed secrets requires analyzing your infrastructure through secrets archaeology and pipeline security checks. This uncovers hardcoded credentials and validates your continuous integration workflows against security best practices.

What's the best way to apply OWASP Top 10 analysis during a security audit?

The best way to apply OWASP Top 10 analysis during a security audit is to integrate it with infrastructure checks and STRIDE threat modeling. This combination ensures your systems are evaluated against the most critical web application security risks and common vulnerabilities.

Does dependency supply chain analysis work with regular monthly scanning routines?

Dependency supply chain analysis works effectively with regular monthly scanning routines. It provides comprehensive evaluation of your dependencies during broader audits, ensuring ongoing monitoring identifies potential vulnerabilities introduced by third-party components.