Ciso review
Unified skill library for Claude, Codex, Cursor, Antigravity & AI agents — 2,658 skills across 15 domains
npx -y skills add sinhoneyy/master-skills --skill ciso-reviewAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
SKILL.md
3.1 KB, 793 tokens by cl100k_base, as published. Nobody here has run it
/cs:ciso-review — CISO Forcing Questions
Command: /cs:ciso-review <plan>
The risk-paranoid threat-modeler. Six questions before any production change that touches customer data or compliance scope.
When to Run
- Before deploying any system that touches PII / PHI / cardholder data
- Before signing a new vendor with data access
- Before a compliance audit (SOC 2, ISO 27001, HIPAA, GDPR)
- Before any architecture decision crossing trust boundaries
- After any near-miss incident
The Six CISO Questions
1. Threat Model
What's the STRIDE threat model for this system, and which threat is most likely?
- Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege.
- Pick the top 3 by likelihood × impact.
2. Blast Radius
If this is fully compromised, what data is exposed and how many users are affected?
- Worst case in plain English.
- Quantify in dollars via FAIR-based ALE.
3. Detection
What signals indicate compromise, and how long until they're triggered (MTTD)?
- Logs alone are not detection.
- Define the detection rule, the alert, and the on-call.
4. Response
Is there an IR runbook for this scenario, and has it been tabletop-tested?
- If no runbook: build one before ship.
- If untested: tabletop before ship.
5. Regulatory Window
What's the regulator notification window if this scenario occurs?
- GDPR: 72h. HIPAA: 60d. State breach laws vary.
- Pre-write the customer comms template.
6. Vendor & Supply Chain
Which third-party vendors are in scope, and what's their security posture?
- Subprocessor list current?
- DPAs in place?
- Last security review per vendor?
Workflow
python ../../../skills/ciso-advisor/scripts/risk_quantifier.py
python ../../../skills/ciso-advisor/scripts/compliance_tracker.py
Output Format
# CISO Review: <plan>
**Date:** YYYY-MM-DD
## Threat Model
- Top threat: <STRIDE category> — <description>
- Likelihood: H/M/L | Impact: H/M/L
- ALE: $X / year
## Blast Radius
- Data exposed (worst case): <description>
- Users affected: N
- Estimated cost: $X
## Detection
- MTTD target: X hours
- Current MTTD: X hours
- Detection rule: <name>
## Response
- IR runbook: ✅ / ❌
- Last tabletop: <date>
## Regulatory
- Frameworks in scope: SOC 2 / ISO 27001 / HIPAA / GDPR
- Notification window: X hours/days
## Vendors
- New vendors added: N
- DPAs signed: N / N
- Security reviews complete: N / N
## Verdict
🟢 SHIP | 🟡 MITIGATE THEN SHIP | 🔴 BLOCK
Routing
/cs:cto-review— architecture alignment/cs:gc-review— DPA, regulatory implications/cs:decide— log risk acceptance/cs:boardroom— for CRITICAL risks
Related
- Agent:
cs-ciso-advisor - Skill:
ciso-advisor - Compliance:
../../../../ra-qm-team/
Version: 1.0.0
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most review quality skills give in 793 tokens
Counted across 1,048 of the 1,783 authors here whose files we hold, read 2026-08-07
- Ask questions one at a timein 81 of 1048, across 64 files
- Provide a recommended answer for each questionin 73 of 1048, across 50 files
- Explore the codebase instead of asking answerable questionsin 66 of 1048, across 42 files
- Resolve dependencies between decisions one-by-onein 42 of 1048, across 17 files
- Interview the user relentlessly about the planin 38 of 1048, across 13 files
- Order findings by severityin 31 of 1048
- Resolve each branch of the decision treein 27 of 1048, across 5 files
- Run a grilling sessionin 26 of 1048, across 5 files
- Update CONTEXT.md immediately when a term is resolvedin 26 of 1048, across 11 files
- Propose precise canonical terms for vague languagein 25 of 1048, across 7 files
- Create documentation files lazilyin 24 of 1048, across 5 files
- Assign severity to every findingin 24 of 1048
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.