Back to Skills

owasp-security

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).

333stars31forksUpdated 8/13/2026

Security Assessment

Safe(96/100)
Security Score96/100

About owasp-security

OWASP Security Best Practices is a defensive reference skill that supplies current OWASP standards to an agent while it writes or reviews code. It targets the recurring problem that automated security review over-reports: a raw pattern match gets flagged as a vulnerability even when the sink is unreachable or already mitigated, which buries the findings that actually matter. The skill grounds review in the OWASP Top 10:2025, ASVS 5.0, the LLM Top 10 (2025), and the Agentic AI security guidance (2026), and insists a finding be confirmed as attacker-controlled input reaching a reachable sink with real blast radius before it is reported.

The core SKILL.md carries a quick-reference table of the 2025 Top 10 with key preventions, a three-step reachability test to run before reporting, and a structured code-review checklist spanning input handling, authentication and sessions, access control, data protection, and error handling. It also shows paired unsafe/safe code patterns for issues such as SQL and command injection. Two load-on-demand reference files extend it: languages.md covers per-language security quirks with unsafe/safe examples for 20-plus languages, and owasp-report.md is a deep-dive across every OWASP 2025-2026 standard including renamed and new categories.

It is aimed at developers and security reviewers who want up-to-date, exploitability-first guidance when auditing web applications, implementing auth, or handling untrusted input. Useful cases include pre-merge security review, threat-informed design discussions, and keeping references current when older category names signal stale advice.

FAQ

What standards does this skill cover?

OWASP Top 10:2025, OWASP ASVS 5.0.0, the OWASP Top 10 for LLM Applications 2025, and the OWASP Top 10 for Agentic Applications 2026, with category names taken verbatim from owasp.org.

How does it reduce false positives in security review?

Before reporting, it requires confirming three things: the input is genuinely attacker-controlled from a real entry point, the sink is reachable given existing validation or middleware, and the blast radius crosses a trust boundary. Severity is rated by exploitability, not by pattern.

Does the skill modify or execute code?

No. It is a reference and review-guidance skill. It supplies checklists, standards, and paired unsafe/safe code examples for the agent to apply; it does not run exploits or change files on its own.

When should I load the reference files?

Load languages.md for per-language security quirks across 20-plus languages, and owasp-report.md for a comprehensive deep-dive on each 2025-2026 standard. Both are loaded on demand rather than upfront.

All Files

3 files
reference/owasp-report.md40.6 KB
View
SKILL.md14.3 KB
View
reference/languages.md9.0 KB
View

Install owasp-security

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill