owasp-asi
25Skill Claude CodeCodex
OWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories.
Skill Claude CodeCodex
OWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories.
Skill Claude CodeCodex
Detect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools.
Skill Claude CodeCodex
Detect command injection, eval/exec usage, remote execution, or arbitrary code loading.
Skill Claude CodeCodex
Detect data exfiltration via URL path encoding and chained webfetch navigation. Covers fake trusted UI injection, letter-level URL path exfiltration, and multi-hop navigation hijacking. Use when the agent has web/URL fetch capability and stores user memory or personal context.
Agent
An automation procedure for deploying a Model Context Protocol (MCP) program from source code. MCP is a standard way for an AI client to connect to tools or data services.
Agent
A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.
Agent
A security-testing agent for MCP servers, which are services that let AI systems call tools and access resources. It checks whether reported vulnerabilities can be exploited in a running server and records supporting evidence.
Agent
A standard way for AI applications to connect to outside data and tools. MCP, short for Model Context Protocol, defines how an AI can discover and use services such as files, databases, or APIs.
Agent
A security-review agent that checks vulnerability reports for real, reproducible threats and filters out false positives. A false positive is an alleged problem that is not actually exploitable or harmful in the stated environment.
Agent
An agent that collects and documents information about a software project, including its structure, technology, dependencies, testing, deployment, data handling, and security-related details. It bases the report on the project's actual files and documentation.
Skill Claude CodeCodex
A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.
Skill Claude CodeCodex
A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin required. Requires AIGBASEURL to be configured. Triggers on: scan AI service, AI vulnerability scan, scan AI infra…
Skill Claude CodeCodex
The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque…
Skill Claude CodeCodex
Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描…
Skill Claude CodeCodex
Use when the user asks to perform browser automation tasks against their logged-in browser: visit and read pages, fill forms, scrape data, click through a flow, regression-test a PR's UI, validate a deployed page. Requires the bsk CLI installed and the browser-skill extension loaded.
Instructions file
Claude Code instructions for Tencent/teamai-cli, covering teamai cli, project overview, tech stack, common commands and release process.
Agent
Search the team knowledge base (skills + learnings + docs + rules + codebase graph) and return a compact, structured summary with docids — instead of dumping full knowledge content into the main conversation. Invoke when the task may benefit from team knowledge context — skip when the user already provided context…
Skill Claude CodeCodex
A codebase-analysis tool that maps large projects across multiple repositories and microservices into structured knowledge, using architecture analysis, code parsing, and a relationship graph.
Agent
A graph-building agent that extracts relationships between existing knowledge-base component documents and organizes them into a structured G1G9 document set.
Agent
A knowledge-base document-generation agent from Tencent’s teamai-cli project, with a defined role, input package, workflow, and method-loading step.
Skill Claude CodeCodex
A team knowledge-sharing tool for contributing useful lessons from a coding session to a shared team knowledge base.
Instructions file CodexOpenCode
A set of instructions for Tencent/YOLO-Master projects, covering AGENTS.md files, startup, directory responsibilities, risky areas, and verification commands.
Instructions file
A set of Claude Code instructions covering project guidance files such as claude.md, required reading, and checks before and after changes.
Skill Claude CodeCodex
Use when the user wants to train, validate, predict, track, export, benchmark, tune, inspect, or orchestrate YOLO-Master / Ultralytics experiments in this repository, including LoRA, MoE, multimodal inference/evaluation, and solutions workflows.