cso — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cso (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
# Suiperpower telemetry. Routes through the CLI so projects.json + Convex stay in sync.
# Silent on failure so the skill never blocks. Opt out: SUIPERPOWER_TELEMETRY=off.
#
# AGENT NOTE: when this skill finishes, run the matching completion command:
# suiperpower track cso build completed
# Or use "failed" / "aborted" if it ended that way.
command -v suiperpower >/dev/null 2>&1 && suiperpower track cso build started >/dev/null 2>&1 &
trueIf TEL_PROMPTED is no, before doing real work, ask the user:
Help suiperpower get better. We track which skills get used and how long they take. No code, no file paths, no PII. Change anytime in ~/.suiperpower/config.json.>
A) Sure, anonymous B) No thanks
Write the answer to ~/.suiperpower/config.json telemetryTier field and create ~/.suiperpower/.telemetry-prompted. Then continue.
Runs a structured infrastructure security audit on a Sui project. Walks through STRIDE threat modeling, OWASP-mapped checks, dependency supply chain verification, RPC/API hardening, key management, and frontend security. Produces a findings report with severity ratings and a remediation plan. Every P0 finding must have a fix or an accepted-risk decision before the audit is declared complete.
review-move instead.ottersec-prep instead.scaffold-project first.debug-move.deploy-to-testnet or deploy-to-mainnet.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
.suiperpower/build-context.md from prior skills. Read it if present.If the project scope is unclear, interview the user for:
.suiperpower/build-context.md with severity levels (P0 critical, P1 high, P2 medium, P3 low)..suiperpower/build-context.md: ## cso session, <timestamp>
- scope: <components audited>
- findings: P0=<n> P1=<n> P2=<n> P3=<n>
- P0 findings resolved: <yes | no, list remaining>
- threat model: STRIDE completed for <components>
- supply chain: <clean | issues found>
- open issues: <list>.suiperpower/build-context.md if it exists.For each component, walk through the six STRIDE categories. See references/security-checklist.md for the Sui-specific STRIDE table.
| Category | Question |
|---|---|
| Spoofing | Can an attacker impersonate a user or admin? |
| Tampering | Can an attacker modify on-chain state, PTBs, or API requests? |
| Repudiation | Can actions be denied without audit trail? |
| Information disclosure | Can sensitive data leak from Move objects, RPC responses, or frontend state? |
| Denial of service | Can an attacker exhaust shared object contention, rate limits, or gas? |
| Elevation of privilege | Can a user escalate to admin via capability leaks or missing auth checks? |
Document findings per component. Assign severity.
npm audit (or equivalent) on the TS/JS project. Flag high and critical findings.Move.toml: are they pinned to a specific rev or tag, not floating?references/supply-chain-audit.md for the full checklist..env files are in .gitignore..suiperpower/build-context.md..suiperpower/intent.md exists and the session was non-trivial (new module, new sponsor integration, or material changes to public functions), recommend verify-against-intent as the next step so drift is caught before shipping.intent.md exists and the session was non-trivial, surface that gap once: offer clarify-intent to backfill, do not force it.Before reporting done, the skill asks itself the following and refuses to declare success if any answer is no:
.suiperpower/build-context.md, not just discussed verbally?If any answer is no, the skill reports the gap and works through it before claiming the audit is complete.
On-demand references (load when relevant to the user's question):
references/security-checklist.md: STRIDE categories with Sui-specific items, OWASP top 10 mapped to Sui patterns.references/supply-chain-audit.md: npm audit workflow, Move dependency verification, package ID pinning.Knowledge docs (load when scope expands beyond what is in references):
skills/data/sui-knowledge/sponsor-docs/walrus.md: Walrus security considerations for encrypted blob storage.External docs (fetch at runtime for the latest guidance):
claude "/suiper:cso <your message>"codex "/cso <your message>"grok, then /cso <your message> in the session~/.cursor/rules/cso.mdc and reference it.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.