All skills
garrytan avatar

/cso

@4a3c6a8 official
by Garry Tangarrytan/gstack135k stars
20,051

Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)

Use this Skill: https://skilld.dev/gh/garrytan/gstack/cso

This session only. Nothing lands on disk.

ACKNOWLEDGEMENTS.md

≈762 tokens on demand. Your agent reads this file only when SKILL.md points to it.

CSO research and source versions

CSO v3 separates supported static evidence, reproduction, proposed repair candidates, and current-source closure. The design is informed by Mozilla's account of hardening Firefox and Codex Security's research-preview description: application context and reproducible verification inform the workflow. Their results are not measurements of CSO.

The domain instructions in sections/audit-phases.md.tmpl identify the versions they use:

Execution details follow primary documentation: Bun compiled executables, Docker contexts, container networking, Docker logging, npm ci, uv CLI, and RubyGems commands. Compiling alone does not suppress Bun configuration or runtime injection variables. Offline dependency preparation must exclude local Python builds during acquisition and defer Gemfile evaluation until offline execution.

Earlier CSO work drew on Trail of Bits' skills for context building and variant analysis, Sentry's skills for research before reporting, and the broader community's security-skill reviews. v3 replaces inherited blanket false-positive exclusions and numerical confidence gates with explicit attacker/control/impact evidence and independent challenge.

CSO accuracy, recall, setup success, and repair correctness are release measurements, not inherited vendor benchmark claims. Qualification requires matched models/budgets, held-out assertions, supported setup failures counted as misses, and zero falsely certified repairs. The presence of documentation or an adapter does not mean its runtime image or release gates have passed.

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    This skill is a security auditing tool that performs automated code and infrastructure scans. It includes various checks for vulnerabilities, secrets, and supply chain risks. All detected external patterns follow standard auditing practices or reference well-known security research and tools.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 4a3c6a8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
What it can do
Runs commands
version
3.0.0
triggers
[
  "security audit",
  "check for vulnerabilities",
  "owasp review"
]
All 2 allowed tools
Bash(~/.claude/skills/gstack/bin/gstack-cso-launcher *)Bash(~/.claude/skills/gstack/bin/gstack-cso-launcher.exe *)
  • security-audit
  • threat-modeling
  • owasp
  • secrets
  • ci-cd
  • dependency-scanning
  • supply-chain
  • vulnerability-scanning
  • stride

README badge

README badge for garrytan/gstack/cso

Performs infrastructure and supply-chain security audits on your codebase, including secrets archaeology, dependency scanning, CI/CD pipeline review, and OWASP Top 10 / STRIDE threat modeling. Runs in two modes: daily for zero-noise scanning or monthly for comprehensive deep scans with lower confidence thresholds.

Generated from the current SKILL.md.

Does this skill perform active vulnerability scanning?
Yes. The skill includes active verification and supports both daily (zero-noise, 8/10 confidence gate) and comprehensive monthly deep scan modes (2/10 bar). It also tracks trends across audit runs.
What security domains does this cover?
It covers infrastructure-first audits including secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, OWASP Top 10, and STRIDE threat modeling.
How do I invoke this skill?
Use voice triggers like "see-so", "security review", "vulnerability scan", or text triggers: "security audit", "check for vulnerabilities", "owasp review", "threat model", "pentest review", "CSO review".
What tools does this skill use?
It leverages Bash, Read, Grep, Glob, Write, Agent, WebSearch, and AskUserQuestion to perform audits and retrieve external threat intelligence.

Generated from the current SKILL.md. These answers refresh after source changes.