Chief Security Officer mode: provides systematic security audits, threat modeling, and supply chain scanning.

Install

mkdir -p .claude/skills/cso && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13596" && unzip -o skill.zip -d .claude/skills/cso && rm skill.zip

Installs to .claude/skills/cso

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification. Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs. Use when: "security audit", "threat model", "pentest review", "OWASP", "CSO review". (gstack) Voice triggers (speech-to-text aliases): "see-so", "see so", "security review", "security check", "vulnerability scan", "run security".
615 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • →Conduct infrastructure-first security audits
  • →Perform secrets archaeology to detect exposed credentials
  • →Scan dependency supply chains for vulnerabilities
  • →Assess CI/CD pipeline security
  • →Apply OWASP Top 10 and STRIDE threat modeling

How it works

The skill conducts security audits by scanning for secrets, analyzing dependency supply chains, and assessing CI/CD security. It applies OWASP and STRIDE methodologies to identify vulnerabilities and reports findings without modifying code.

Inputs & outputs

You give it
A request for a security audit, threat model, or vulnerability scan.
You get back
A security audit report with findings, recommendations, and a disclaimer, but no code modifications.

When to use cso

  • →Run security audit
  • →Perform threat model review
  • →Check for vulnerabilities

About cso

This skill conducts comprehensive security audits, covering secret detection, dependency supply chains, and CI/CD security. It follows OWASP and STRIDE methodologies to verify infrastructure integrity.

|

When not to use it

  • →When seeking a substitute for a professional security audit
  • →When expecting complete coverage beyond common vulnerability patterns
  • →When relying on the tool as the only line of defense for production systems

Limitations

  • →This tool is not a substitute for a professional security audit
  • →LLMs can miss subtle vulnerabilities, misunderstand complex auth flows, and produce false negatives
  • →Never modify code; produce findings and recommendations only

How it compares

This skill automates security audits by applying various methodologies and scanning techniques to identify vulnerabilities, providing a structured report without modifying code, unlike a manual audit that might involve direct code changes.

Compared to similar skills

cso side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
cso (this skill)05moCautionAdvanced
secrets-management55moReviewAdvanced
security-scanning-security-hardening35moNo flagsAdvanced
sast-configuration35moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

Search skills

Search the agent skills registry