‹ 首页

gstack-cso

@dirtytrii · 收录于 1 周前 · 上游提交 1 周前

GStack CSO method for broad infrastructure-first security posture review, threat areas, severity calibration, and safe remediation scope.

适合你,如果需要系统性地审查基础设施安全风险并确定修复优先级

/ 通过 npx 安装 校验哈希
npx oh-my-skill add dirtytrii/codex-skills/gstack-cso
/ 通过 bash 安装
curl -fsSL https://oh-my-skill.com/install.sh | bash -s -- dirtytrii/codex-skills/gstack-cso
/ 已经装过?验证本机副本,不用重装
npx oh-my-skill verify dirtytrii/codex-skills/gstack-cso
安装目标可用 --agent / --scope 或 --to 明确指定;省略时只会在唯一已存在的 agent 目录上自动选择,零命中或多命中会停止并提示。content_hash 缺失或不一致均拒装。
9GitHub stars
~384最小装载
~384含声明引用
~432文本包总量
索引托管

怎么用

商店整理自技能原文 · 版本 f142db6 · 表述以原文为准
它做什么

装上后,Claude 会按照 GStack CSO 方法审查基础设施安全态势,识别威胁领域、评估严重性,并给出安全修复范围。

什么时候触发

当用户要求进行广泛的安全态势审查,或涉及基础设施、认证、密钥、部署、数据暴露等风险时触发。

装好后可以这样说
Claude 会输出威胁领域、发现、严重性等。
Claude 会聚焦于密钥和部署安全。
技能原文 SKILL.md作者撰写 · MIT · f142db6

GStack CSO Adapter

This is a Codex role-system adapter for Garry Tan's gstack gstack-cso method.

When To Use

Use this when:

  • broad security posture needs review;
  • infrastructure, auth, secrets, deployment, or data exposure risks are in scope;
  • architecture wants security gates;
  • the user explicitly invokes $gstack-cso.
Workflow
  1. Keep the active role boundary. Do not expand scope just because this gstack method is useful.
  2. Read the relevant repo/docs/evidence first when the task depends on current state.
  3. Read ../gstack/references/methodology.md if you need the shared method map, then use the section named QA, Security, And Release Methods.
  4. Produce: threat areas, findings, severity, safe evidence, remediation scope, and residual risk.
  5. Return the result in the active role's normal format, including boundaries, validation, and unresolved decisions when applicable.
Boundaries
  • Treat upstream gstack as external methodology, not local-owned project state.
  • Do not run upstream gstack runtime, telemetry, browser-cookie import, upgrade checks, or host routing injection automatically.
  • Do not create or edit CLAUDE.md, .claude/, .agents/, or upstream routing files unless the user explicitly asks for upstream gstack installation work.
  • Do not write files, commit, push, deploy, restart, migrate, clean, delete, or change production unless the active role prompt explicitly allows it.
  • Preserve this repository's QA versus 测试 split: formal test cases/reports belong to 测试 and $test-case-report-builder.
  • Do not perform destructive testing, brute force, exfiltration, or unauthorized modification.
按 MIT 许可原样转载,未经改动 · 在 GitHub 查看 →

评论

登录即可评论;带「已验证安装」的,是发布者名下有本店的安装或持有记录。