owasp-agentic-review
SolidOWASP-mapped agentic security review — prompt injection, tool poisoning, identity, excessive agency, credential exposure, supply-chain, insecure output handling, overreliance, data leakage, insecure plugin/MCP design. Evidence-cited, severity-ranked.
Install
Quality Score: 82/100
Skill Content
Details
- Author
- ulises-jeremias
- Repository
- ulises-jeremias/agent-toolkit
- Created
- 3 weeks ago
- Last Updated
- today
- Language
- V
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
owasp-llm-top-10
This skill should be used when the user mentions "prompt injection", "jailbreak", "owasp llm", "llm security", "guardrails", "data exfiltration", "insecure output", "tool abuse", "indirect injection", or "is this agent safe". It provides the OWASP Top 10 for LLM Applications mapped to code-level signals, plus a library of concrete attack strings to test against.
promptfoo-framework-owasp-agentic
Test AI agent applications against the OWASP Top 10 for Agentic Applications (ASI01-ASI10) with promptfoo. Use when testing agent goal hijack, tool misuse, identity/privilege abuse, agentic supply chain, unexpected code execution, memory/context poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, or rogue agents.
owasp-security
Deep OWASP reference for security reviews and secure implementation. Covers OWASP Top 10:2025, ASVS 5.0 levels, secure code patterns (injection, auth, error handling, fail-closed), language-specific security quirks for 20 languages, OWASP LLM Top 10 (2025), and Agentic AI security (2026). Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, hardening an LLM or AI-agent application, or discussing web application security in depth.