Chief Security Officer mode: provides systematic security audits, threat modeling, and supply chain scanning.
Install
mkdir -p .claude/skills/cso && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13596" && unzip -o skill.zip -d .claude/skills/cso && rm skill.zipInstalls to .claude/skills/cso
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification. Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs. Use when: "security audit", "threat model", "pentest review", "OWASP", "CSO review". (gstack) Voice triggers (speech-to-text aliases): "see-so", "see so", "security review", "security check", "vulnerability scan", "run security".Key capabilities
- →Conduct infrastructure-first security audits
- →Perform secrets archaeology to detect exposed credentials
- →Scan dependency supply chains for vulnerabilities
- →Assess CI/CD pipeline security
- →Apply OWASP Top 10 and STRIDE threat modeling
How it works
The skill conducts security audits by scanning for secrets, analyzing dependency supply chains, and assessing CI/CD security. It applies OWASP and STRIDE methodologies to identify vulnerabilities and reports findings without modifying code.
Inputs & outputs
When to use cso
- →Run security audit
- →Perform threat model review
- →Check for vulnerabilities
About cso
This skill conducts comprehensive security audits, covering secret detection, dependency supply chains, and CI/CD security. It follows OWASP and STRIDE methodologies to verify infrastructure integrity.
|
When not to use it
- →When seeking a substitute for a professional security audit
- →When expecting complete coverage beyond common vulnerability patterns
- →When relying on the tool as the only line of defense for production systems
Limitations
- →This tool is not a substitute for a professional security audit
- →LLMs can miss subtle vulnerabilities, misunderstand complex auth flows, and produce false negatives
- →Never modify code; produce findings and recommendations only
How it compares
This skill automates security audits by applying various methodologies and scanning techniques to identify vulnerabilities, providing a structured report without modifying code, unlike a manual audit that might involve direct code changes.
Compared to similar skills
cso side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| cso (this skill) | 0 | 5mo | Caution | Advanced |
| secrets-management | 5 | 5mo | Review | Advanced |
| security-scanning-security-hardening | 3 | 5mo | No flags | Advanced |
| sast-configuration | 3 | 5mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by mostafasudo
View all by mostafasudo →You might also like
secrets-management
wshobson
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
security-scanning-security-hardening
sickn33
Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
sast-configuration
wshobson
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.
dependency-auditor
alirezarezvani
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.
mcp-security-scan
cisco-ai-defense
Scans MCP servers, tools, prompts, and resources for security vulnerabilities using YARA rules, LLM analysis, and Cisco AI Defense API. Use this skill when the user wants to check MCP servers for security issues, detect prompt injection, tool poisoning, or analyze MCP configurations for threats.
fix-cves
okteto
Fix all CVEs in the Okteto CLI Docker image by scanning with Trivy and updating vulnerable dependencies and binaries