owasp skills

192 tagged owasp, measured the same way as everything else here.

Browse within: appsec 55ai-security 41pentest 41audit 27owasp-juice-shop 27owasp-llm 27owasp-llm-top-10 27cybersecurity 21devsecops 21hardening 20penetration-testing 18threat-modeling 18compliance 17api-security 14

xalgorix/xalgorix

Skill Claude CodeCodex

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating…

942 2d ago A 108 tokens original Apache-2.0

xalgorix/xalgorix

Skill Claude CodeCodex

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not…

942 2d ago A 114 tokens original Apache-2.0

ship-safe-baseline

03

asamassekou10/ship-safe

Skill Claude CodeCodex

Manage your security baseline — accept current findings as known debt, then only report new regressions on future scans. Use when the user wants to adopt security scanning incrementally or suppress existing findings.

828 3d ago A 43 tokens original MIT

ship-safe-ci

04

asamassekou10/ship-safe

Skill Claude CodeCodex

Run Ship Safe in CI mode — compact output, exit codes, SARIF generation. Use when the user wants to set up CI/CD security gates or test their pipeline configuration.

828 3d ago A 39 tokens original MIT

ship-safe

05

asamassekou10/ship-safe

Skill Claude CodeCodex

Run a full security audit on this project — 16 agents scan for secrets, injections, auth bypass, SSRF, supply chain, Supabase RLS, MCP security, agentic AI, RAG poisoning, PII compliance, and more. Use when the user wants a security audit, vulnerability scan, or asks if their code is safe to ship.

828 3d ago A 75 tokens original MIT

super-helper

07

HeadyZhang/agent-audit

Skill Claude CodeCodex

A helpful assistant that installs a launchd daemon for background processing.

224 1mo ago E 16 tokens original MIT

dast-nuclei

09

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applications, APIs, and infrastructure. Use when: (1) Performing rapid vulnerability scanning with automated CVE detection, (2)…

201 4mo ago A 129 tokens

aozyildirim/Agena

Skill Claude CodeCodex

A paranoid OWASP-Top-10-aware system prompt for AI code review that traces data flow, treats every input as malicious, maps each finding to an OWASP category, and outputs a structured Summary / Findings / Severity / Score block reviewers can act on.

98 1mo ago A 59 tokens original MIT

pentest

12

Strategic-Automation/violin

Skill Claude CodeCodex

Supervised authorized pentest: scope, route, validate, report.

84 yesterday A 17 tokens original MIT

web-app

13

Strategic-Automation/violin

Skill Claude CodeCodex

Web application testing: injection and client-side flaws.

84 yesterday A 13 tokens original MIT

behavior-verifier

15

open-agent-ai-security/praxen

Skill Claude CodeCodex

Run a Praxen behavior analysis against an AI agent — or author the Worker Remit that drives one. Praxen verifies intended vs observed behavior by comparing an agent's declared policy (Worker Remit) against available evidence — source code, live deployment state (memory files, logs, configs), governance docs, or…

59 2d ago C 184 tokens original Apache-2.0

PulverizeDirector/b01-gbrain-security

Skill Claude CodeCodex

🔒 Threat Intelligence Brain — Self-wiring knowledge graph for threats, vulnerabilities and security incidents. Derived from gbrain (garrytan/gbrain). Security audits, vulnerability management, GDPR/SOC2.

47 4mo ago A 48 tokens