LaunchKit · 2026

Setup & Installation

npx skills add https://github.com/garrytan/gstack --skill cso
or paste the link and ask your coding assistant to install it
https://github.com/garrytan/gstack/tree/main/cso
View on GitHub

What This Skill Does

Runs a multi-phase security audit across a codebase. Covers secrets in git history, dependency supply chains, CI/CD pipeline risks, LLM-specific vulnerabilities, OWASP Top 10, and STRIDE threat modeling. Produces a findings report with exploit scenarios, severity ratings, and remediation guidance. Two modes: daily (8/10 confidence gate, zero noise) and comprehensive (2/10 bar, surfaces more candidates).

Manually checking 14 attack surface categories across git history, CI configs, dependencies, and application code takes hours and most teams skip the archaeology entirely — this covers all of it in one pass with confidence-gated filtering that cuts noise before it reaches your report.

When to use it

  • Scanning git history for leaked AWS keys and OAuth tokens before a repo goes public
  • Auditing GitHub Actions workflows for pull_request_target misuse and unpinned third-party actions
  • Checking webhook handlers for missing HMAC signature verification across the entire codebase
  • Running LLM feature audits to trace user input paths that reach system prompts
  • Tracking security posture trends across audit runs before a SOC 2 or compliance review