cso
Run a CSO-style customer signal review on a Sui product. Use when the user wants a CSO or customer signal review.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Run a CSO-style customer signal review on a Sui product. Use when the user wants a CSO or customer signal review.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Pick a brand name, color palette, or typography for a Sui product. Use when the user wants to name or brand a Sui project.
Build an AI agent that signs Sui transactions or runs onchain actions. Use when the user wants an AI agent on Sui.
Build a Sui data indexer or analytics pipeline. Use when the user wants to index Sui events, build a pipeline, or query Sui RPC data.
Build a mobile Sui app with React Native or the Sui Mobile SDK. Use when the user wants iOS, Android, or mobile Sui flows.
Pair with a coding agent to build a Sui MVP step by step. Use when the user wants to build the MVP iteratively with an agent.
Author Sui Move modules and packages with a senior Move dev as your pair. Use when the user wants to write, build, author, add, or scaffold Move code, smart contracts, or Sui programs at the module or function level, in any phrasing.
| name | cso |
| description | Run a CSO-style customer signal review on a Sui product. Use when the user wants a CSO or customer signal review. |
# Suiperpower telemetry. Routes through the CLI so projects.json + Convex stay in sync.
# Silent on failure so the skill never blocks. Opt out: SUIPERPOWER_TELEMETRY=off.
#
# AGENT NOTE: when this skill finishes, run the matching completion command:
# suiperpower track cso build completed
# Or use "failed" / "aborted" if it ended that way.
command -v suiperpower >/dev/null 2>&1 && suiperpower track cso build started >/dev/null 2>&1 &
true
If TEL_PROMPTED is no, before doing real work, ask the user:
Help suiperpower get better. We track which skills get used and how long they take. No code, no file paths, no PII. Change anytime in
~/.suiperpower/config.json.A) Sure, anonymous B) No thanks
Write the answer to ~/.suiperpower/config.json telemetryTier field and create ~/.suiperpower/.telemetry-prompted. Then continue.
Runs a structured infrastructure security audit on a Sui project. Walks through STRIDE threat modeling, OWASP-mapped checks, dependency supply chain verification, RPC/API hardening, key management, and frontend security. Produces a findings report with severity ratings and a remediation plan. Every P0 finding must have a fix or an accepted-risk decision before the audit is declared complete.
review-move instead.ottersec-prep instead.scaffold-project first.debug-move.deploy-to-testnet or deploy-to-mainnet.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
.suiperpower/build-context.md from prior skills. Read it if present.If the project scope is unclear, interview the user for:
A structured findings report appended to .suiperpower/build-context.md with severity levels (P0 critical, P1 high, P2 medium, P3 low).
A remediation plan with concrete fix instructions for each P0 and P1 finding.
Append to .suiperpower/build-context.md:
## cso session, <timestamp>
- scope: <components audited>
- findings: P0=<n> P1=<n> P2=<n> P3=<n>
- P0 findings resolved: <yes | no, list remaining>
- threat model: STRIDE completed for <components>
- supply chain: <clean | issues found>
- open issues: <list>
.suiperpower/build-context.md if it exists.For each component, walk through the six STRIDE categories. See references/security-checklist.md for the Sui-specific STRIDE table.
| Category | Question |
|---|---|
| Spoofing | Can an attacker impersonate a user or admin? |
| Tampering | Can an attacker modify on-chain state, PTBs, or API requests? |
| Repudiation | Can actions be denied without audit trail? |
| Information disclosure | Can sensitive data leak from Move objects, RPC responses, or frontend state? |
| Denial of service | Can an attacker exhaust shared object contention, rate limits, or gas? |
| Elevation of privilege | Can a user escalate to admin via capability leaks or missing auth checks? |
Document findings per component. Assign severity.
npm audit (or equivalent) on the TS/JS project. Flag high and critical findings.Move.toml: are they pinned to a specific rev or tag, not floating?references/supply-chain-audit.md for the full checklist..env files are in .gitignore..suiperpower/build-context.md..suiperpower/intent.md exists and the session was non-trivial (new module, new sponsor integration, or material changes to public functions), recommend verify-against-intent as the next step so drift is caught before shipping.intent.md exists and the session was non-trivial, surface that gap once: offer clarify-intent to backfill, do not force it.Before reporting done, the skill asks itself the following and refuses to declare success if any answer is no:
.suiperpower/build-context.md, not just discussed verbally?If any answer is no, the skill reports the gap and works through it before claiming the audit is complete.
On-demand references (load when relevant to the user's question):
references/security-checklist.md: STRIDE categories with Sui-specific items, OWASP top 10 mapped to Sui patterns.references/supply-chain-audit.md: npm audit workflow, Move dependency verification, package ID pinning.Knowledge docs (load when scope expands beyond what is in references):
skills/data/sui-knowledge/sponsor-docs/walrus.md: Walrus security considerations for encrypted blob storage.External docs (fetch at runtime for the latest guidance):
claude "/suiper:cso <your message>"codex "/cso <your message>"grok, then /cso <your message> in the session~/.cursor/rules/cso.mdc and reference it.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.