
de gstack (Korean docs)43
Manual Chief Security Officer auditing skill that runs an infrastructure-first security review: secrets archaeology, supply-chain checks, CI/CD analysis, LLM se
Provides a comprehensive, infrastructure-first security audit workflow designed as a Chief Security Officer persona. It guides the agent through stack detection, secrets archaeology, dependency and CI/CD analysis, webhook and integration checks, LLM/AI-specific security, skill supply-chain scanning, OWASP Top 10 validation, STRIDE threat modeling, and active verification filters. Produces a structured findings report with exploit scenarios and remediation recommendations.
Invoke manually with /cso for daily zero-noise audits or /cso --comprehensive for deeper monthly scans. Use when you need a first-pass security posture review, trend tracking across audits, or to triage high-risk CI/dependency issues. Not intended to run automatically — manual trigger only.
Designed for Claude Code environments and gstack-enabled Claude agent setups; expects Bash, Grep, Read, Write, WebSearch and Agent tool access.
Cette compétence n'a pas encore été examinée par notre pipeline d'audit automatisé.
Plan Design Review
Revue interactive des plans de design avec un œil de designer : évalue les dimensions, identifie les lacunes et édite le plan pour ajouter les décisions UI et les états d'interaction manquants.
Canary — Moniteur Post-déploiement
Moniteur canary post-déploiement qui surveille les pages de production pour les erreurs console, les régressions de performance et les échecs de page ; capture des captures d'écran et les compare