owasp agents

52 tagged owasp, measured the same way as everything else here.

Browse within: appsec 46ai-security 24owasp-juice-shop 23owasp-llm 23owasp-llm-top-10 23red-team 18application-security 5best-practices 5cheatsheets 5code 5

OWASP/CheatSheetSeries

Agent Claude Code

Duplication and placement reviewer for OWASP cheat sheet changes. Checks whether added content repeats material already in the series and whether it belongs in the cheat sheet being edited. Invoked by /review-cheatsheet-pr.

33k +11 today A 52 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Link and source-quality auditor for OWASP cheat sheet changes. Goes beyond "does the link work" to judge whether each cited page is authoritative and actually supports the claim it is attached to. Invoked by /review-cheatsheet-pr.

33k +11 today A 56 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Developer-practicality reviewer for OWASP cheat sheet changes. Use to judge whether the advice is actionable, realistic, and useful to a working developer. Invoked by /review-cheatsheet-pr.

33k +11 today A 49 tokens CC-BY-SA-4.0

security-reviewer

04

rohitg00/skillkit

Agent

Security vulnerability detection and remediation specialist. OWASP Top 10, secrets, injection.

1.5k 3mo ago A 20 tokens original Apache-2.0

appsec-foundry/appsec-advisor

Agent

INTERNAL — Stage 4 of the create-threat-model skill. Rewrites the prose of an assembled threat model for clarity and consistency, and changes nothing else. Reads the bounded projection at .dispatch-context/editorial/blocks.json and writes one plan to .dispatch-context/editorial/plan.json; applyeditorialplan.py…

16 changed today A 90 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched cross-component threat triage; validates rating consistency and prioritization, writes .triage-flags.json, and annotates .threats-merged.json.

16 changed today A 45 tokens

security-scanner

08

Wishmakingfairy/vibecheck

Agent

Deep codebase security scanner. Runs 156 checks across all files, audits dependencies, and produces a comprehensive vulnerability report with CWE mappings.

4 5mo ago A 31 tokens original MIT

attack-scenario

09

morodomi/redteam-skills

Agent

An agent that turns detected vulnerabilities into concrete attack scenarios by analysing how weaknesses can be chained together.

2 6mo ago A 35 tokens original MIT

csrf-attacker

10

morodomi/redteam-skills

Agent

A static code-analysis agent that looks for Cross-Site Request Forgery (CSRF), an attack where a victim’s browser is tricked into sending an unwanted request to a site where they are signed in.

2 6mo ago A 35 tokens original MIT

wordpress-attacker

11

morodomi/redteam-skills

Agent

A security-checking agent for WordPress, the software used to build many websites, that looks for unsafe coding patterns in the source code.

2 6mo ago A 36 tokens original MIT

security-auditor

12

joaovicdev/claude-owasp-10

Agent

Read-only auditor dispatched by /api-secure-report to evaluate one slice of a codebase — a group of routes, or one cross-cutting area — against assigned OWASP Top 10:2025 review questions. Not for direct invocation.

2 6d ago A 54 tokens original MIT