/cso — Chief Security Officer Mode

Skill mới trong bộ claudekit — Infrastructure-first security audit. Secrets archaeology, dependency supply chain, CI/CD pipeline, AI/LLM security, OWASP Top 10, STRIDE threat modeling. 2 modes: daily (zero-noise) vs comprehensive (deep monthly scan). Trend tracking.

Tổng quan

/cso là bảo vệ toàn diện. Quét: secrets, dependencies, CI/CD, OWASP, STRIDE, AI risks. 2 chế độ:
  • Daily — 10 min, high-confidence, zero-noise
  • Comprehensive — 30+ min, all checks, monthly
Trend tracking so sánh audits qua thời gian để catch emerging patterns.

Prefix & flags


Workflow

1

Daily audit (zero-noise)

Chỉ critical findings (confidence > 8/10): hardcoded keys, CVSS > 9.0, overly permissive secrets.
2

Comprehensive audit (monthly)

All checks: secrets archaeology, dependencies, CI/CD, OWASP Top 10, STRIDE, AI risks.
3

Trend tracking

Compare vs last audit. New risks? Hotspots? Emerging patterns.
4

Export for compliance

Share dengan auditors, compliance team.

Ví dụ

Daily audit

Output: 3 issues (1 critical secrets, 2 high CVEs). FAIL gate.

Comprehensive + trend

Output: 12 findings. Trend: 3 new risks (hotspot: src/payment/). Recommend security review.

Skip AI checks


So sánh skill khác


Common pitfalls

  • Chạy comprehensive thường xuyên: Alert fatigue. Daily hàng ngày, comprehensive 1x/tháng.
  • Ignore findings: FAIL = critical blockers. Fix, don’t skip.
  • No historical baseline: First run dùng comprehensive để establish baseline.
  • Skip LLM checks (dùng /skip-ai): OK nếu project không dùng LLM.

FAQ

Daily: Hàng ngày, 10 min, critical only, zero-noise. Comprehensive: 1x/tháng, 35 min, all checks.
FAIL = critical blockers. Fix trước proceed. Override với caution: /cso daily --override "reason".
.github/cso-audits/ (per-run JSON). CI integration: auto-track trend.
Scan API calls, prompt injection, jailbreak risks, API key leaks. Dùng --skip-ai nếu no LLM.

Xem thêm