Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Infrastructure-first security audit across 14 phases: attack surface mapping, secrets archaeology (git history), supply chain analysis, CI/CD pipeline security, LLM/AI threat detection, OWASP Top 10, STRIDE threat modeling. Confidence gates, exploit scenarios, parallel verification, trend tracking. Read-only.
.claude/skills/paperclipai-cso/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-15 | ✗→✓ | ▲ Improved | -23% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 29% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 10% | 0% |
| case-06 | ✓→✓ | = Same ✓ | -6% | 0% |
| case-07 | ✓→✓ | = Same ✓ | 8% | 0% |
name: cso description: > Infrastructure-first security audit across 14 phases: attack surface mapping, secrets archaeology (git history), supply chain analysis, CI/CD pipeline security, LLM/AI threat detection, OWASP Top 10, STRIDE threat modeling. Confidence gates, exploit scenarios, parallel verification, trend tracking. Read-only. metadata: sources:
repo: garrytan/gstack path: cso/SKILL.md commit: f4bbfaa5bdfd2d6ce59541c2145432febde57fed attribution: Garry Tan license: MIT usage: referenced
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 18,822 | 11,390 | -39% | 1 | 1 | 0% | 2,149 | 1,195 | -44% | 0 | 0 | — |
case-02 | pass→pass | 25,371 | 27,798 | +10% | 1 | 1 | 0% | 2,326 | 3,008 | +29% | 0 | 0 | — |
case-03 | fail→fail | 18,622 | 10,908 | -41% | 1 | 1 | 0% | 2,051 | 1,234 | -40% | 0 | 0 | — |
case-04 | pass→pass | 7,482 | 5,152 | -31% | 1 | 1 | 0% | 473 | 521 | +10% | 0 | 0 | — |
case-05 | fail→fail | 28,269 | 21,384 | -24% | 1 | 1 | 0% | 5,568 | 5,422 | -3% | 0 | 0 | — |
case-06 | pass→pass | 11,027 | 17,822 | +62% | 1 | 1 | 0% | 2,041 | 1,914 | -6% | 0 | 0 | — |
case-07 | pass→pass | 18,069 | 17,656 | -2% | 1 | 1 | 0% | 2,856 | 3,084 | +8% | 0 | 0 | — |
case-08 | pass→pass | 20,341 | 11,587 | -43% | 1 | 1 | 0% | 2,712 | 1,856 | -32% | 0 | 0 | — |
case-09 | pass→pass | 14,079 | 15,537 | +10% | 1 | 1 | 0% | 2,531 | 2,649 | +5% | 0 | 0 | — |
case-10 | pass→pass | 17,532 | 22,494 | +28% | 1 | 1 | 0% | 2,822 | 4,001 | +42% | 0 | 0 | — |
case-11 | pass→pass | 17,369 | 20,860 | +20% | 1 | 1 | 0% | 2,860 | 3,974 | +39% | 0 | 0 | — |
case-12 | pass→pass | 16,775 | 13,563 | -19% | 1 | 1 | 0% | 2,680 | 2,343 | -13% | 0 | 0 | — |
case-13 | pass→pass | 14,925 | 18,551 | +24% | 1 | 1 | 0% | 2,538 | 3,275 | +29% | 0 | 0 | — |
case-14 | pass→pass | 19,519 | 18,969 | -3% | 1 | 1 | 0% | 2,581 | 2,674 | +4% | 0 | 0 | — |
case-15 | fail→pass | 9,294 | 6,288 | -32% | 1 | 1 | 0% | 1,446 | 1,114 | -23% | 0 | 0 | — |
case-16 | pass→pass | 15,225 | 10,101 | -34% | 1 | 1 | 0% | 2,091 | 1,816 | -13% | 0 | 0 | — |
case-17 | pass→pass | 11,927 | 14,872 | +25% | 1 | 1 | 0% | 2,079 | 2,847 | +37% | 0 | 0 | — |
case-18 | pass→pass | 11,411 | 11,760 | +3% | 1 | 1 | 0% | 1,876 | 2,161 | +15% | 0 | 0 | — |
case-19 | pass→pass | 14,999 | 12,224 | -19% | 1 | 1 | 0% | 2,076 | 2,239 | +8% | 0 | 0 | — |
case-20 | pass→pass | 13,280 | 13,701 | +3% | 1 | 1 | 0% | 2,302 | 2,427 | +5% | 0 | 0 | — |
case-21 | pass→pass | 15,596 | 15,340 | -2% | 1 | 1 | 0% | 2,379 | 2,182 | -8% | 0 | 0 | — |
case-22 | pass→pass | 12,552 | 15,033 | +20% | 1 | 1 | 0% | 2,449 | 2,617 | +7% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of 0 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.