gstack-cso
GStack CSO method for broad infrastructure-first security posture review, threat areas, severity calibration, and safe remediation scope.
适合你,如果需要系统性地审查基础设施安全风险并确定修复优先级
/ 通过 npx 安装 校验哈希
npx oh-my-skill add dirtytrii/codex-skills/gstack-cso/ 通过 bash 安装
curl -fsSL https://oh-my-skill.com/install.sh | bash -s -- dirtytrii/codex-skills/gstack-cso/ 已经装过?验证本机副本,不用重装
npx oh-my-skill verify dirtytrii/codex-skills/gstack-cso安装目标可用 --agent / --scope 或 --to 明确指定;省略时只会在唯一已存在的 agent 目录上自动选择,零命中或多命中会停止并提示。content_hash 缺失或不一致均拒装。
9GitHub stars
~384最小装载
~384含声明引用
~432文本包总量
索引托管
怎么用
商店整理自技能原文 · 版本 f142db6 · 表述以原文为准它做什么
装上后,Claude 会按照 GStack CSO 方法审查基础设施安全态势,识别威胁领域、评估严重性,并给出安全修复范围。
什么时候触发
当用户要求进行广泛的安全态势审查,或涉及基础设施、认证、密钥、部署、数据暴露等风险时触发。
装好后可以这样说
Claude 会输出威胁领域、发现、严重性等。
Claude 会聚焦于密钥和部署安全。
技能原文 SKILL.md
GStack CSO Adapter
This is a Codex role-system adapter for Garry Tan's gstack gstack-cso method.
When To Use
Use this when:
- broad security posture needs review;
- infrastructure, auth, secrets, deployment, or data exposure risks are in scope;
- architecture wants security gates;
- the user explicitly invokes
$gstack-cso.
Workflow
- Keep the active role boundary. Do not expand scope just because this gstack method is useful.
- Read the relevant repo/docs/evidence first when the task depends on current state.
- Read
../gstack/references/methodology.mdif you need the shared method map, then use the section namedQA, Security, And Release Methods. - Produce: threat areas, findings, severity, safe evidence, remediation scope, and residual risk.
- Return the result in the active role's normal format, including boundaries, validation, and unresolved decisions when applicable.
Boundaries
- Treat upstream gstack as external methodology, not local-owned project state.
- Do not run upstream gstack runtime, telemetry, browser-cookie import, upgrade checks, or host routing injection automatically.
- Do not create or edit
CLAUDE.md,.claude/,.agents/, or upstream routing files unless the user explicitly asks for upstream gstack installation work. - Do not write files, commit, push, deploy, restart, migrate, clean, delete, or change production unless the active role prompt explicitly allows it.
- Preserve this repository's
QAversus测试split: formal test cases/reports belong to测试and$test-case-report-builder. - Do not perform destructive testing, brute force, exfiltration, or unauthorized modification.
按 MIT 许可原样转载,未经改动 · 在 GitHub 查看 →
评论
登录即可评论;带「已验证安装」的,是发布者名下有本店的安装或持有记录。
…