scholarly360/owasp-top10-web-skills

Agent Skills for OWASP Top 10 Application Security Risks (https://owasp.org/Top10/2025/)

22Stars on the repository
10Mods indexed here, across every type
5mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Use this skill whenever you need to audit, test, or fix Authentication Failures (OWASP A07:2025) in Python web applications — especially FastAPI and Flask. Triggers include: any mention of JWT security, session management, brute force protection, credential stuffing, password policy, MFA enforcement, login rate…

not rated 22 +1 5mo ago A 166 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Security testing skill for A01:2025 Broken Access Control — the #1 OWASP risk for two consecutive cycles. Use this skill whenever the user asks about: access control vulnerabilities, IDOR (insecure direct object references), authorization bugs, SSRF testing, CORS misconfiguration, privilege escalation, JWT/session…

not rated 22 +1 5mo ago B 146 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Detect, audit, and remediate A04:2025 Cryptographic Failures in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about crypto security, password hashing, JWT configuration, TLS/SSL verification, weak randomness, hardcoded secrets, or any code using hashlib, random, ssl, jwt, passlib…

not rated 22 +1 5mo ago A 125 tokens original MIT

injection

04

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Expert Python security testing skill for OWASP A05:2025 — Injection vulnerabilities in FastAPI and Flask applications. Use this skill whenever the user asks about: SQL injection, XSS, SSTI (Server-Side Template Injection), OS command injection, ORM injection, LLM prompt injection, input validation, parameterized…

not rated 22 +1 5mo ago A 176 tokens original MIT

insecure-design

05

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Detect, analyze, and remediate OWASP A06:2025 Insecure Design vulnerabilities in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about architecture-level security flaws, threat modeling, rate limiting gaps, business logic vulnerabilities, insecure file uploads, race conditions…

not rated 22 +1 5mo ago A 161 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Detect, analyze, and remediate OWASP A10:2025 — Mishandling of Exceptional Conditions in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about error handling security, exception management, fail-open vulnerabilities, stack trace exposure, uncaught exceptions, transaction rollback…

not rated 22 +1 5mo ago A 150 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Use this skill whenever auditing, reviewing, or testing Python web applications (FastAPI or Flask) for OWASP A09:2025 — Security Logging & Alerting Failures. Trigger this skill when the user mentions: logging security, audit trails, log injection, sensitive data in logs, alerting gaps, insufficient logging, SIEM…

not rated 22 +1 5mo ago A 161 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Detect, audit, and remediate Security Misconfiguration vulnerabilities (OWASP A02:2025) in Python web applications — especially FastAPI and Flask. Use this skill whenever a user asks about: hardening a Python/FastAPI/Flask app, checking for debug mode leaks, missing security headers, exposed API docs, hardcoded…

not rated 22 +1 5mo ago A 155 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Security testing skill for OWASP A08:2025 — Software or Data Integrity Failures in Python web applications (FastAPI and Flask). Use this skill whenever the user wants to audit, detect, test, or fix integrity vulnerabilities including: insecure deserialization (pickle, yaml, jsonpickle, dill), mass assignment flaws…

not rated 22 +1 5mo ago A 142 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Expert guidance on detecting, assessing, and remediating Software Supply Chain Failures (OWASP A03:2025) in Python applications — the highest-exploit-score category in the 2025 OWASP Top 10. Use this skill whenever the user mentions dependency scanning, vulnerable packages, SBOMs, pip-audit, safety check, lockfile…

not rated 22 +1 5mo ago A 151 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: