Repository
OWASP/secure-agent-playbook agent skills
- skills
- 14
- GitHub stars
- 187
GitHub description: “OWASP Secure Agent Playbook Project”
- Stars
- 187 (25 forks)
- Licence
- Unknown
- Last push
- Sep 2026
- Created
- Mar 2026
Install all skills
npx skills add OWASP/secure-agent-playbookAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in OWASP/secure-agent-playbook, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written. | OWASP/ | 187 | — | ~4.6k | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 2 | Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations… | OWASP/ | 187 | — | ~4.6k | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 3 | Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary… | OWASP/ | 187 | — | ~5.8k | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 4 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 187 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 5 | Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. | OWASP/ | 187 | — | ~876 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 6 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 187 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 7 | Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 187 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 8 | Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). | OWASP/ | 187 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 9 | Security review of MCP (Model Context Protocol) server implementations and configurations. | OWASP/ | 187 | — | ~574 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 10 | Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. | OWASP/ | 187 | — | ~622 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 11 | Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy. | OWASP/ | 187 | — | ~758 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 12 | 12.Sca Audit Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. | OWASP/ | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 13 | Security-first development guidance based on OWASP ASVS (Application Security Verification Standard). | OWASP/ | 187 | — | ~8.1k | Automated safety check: Pass | Unknown | 13 days ago |
| 14 | Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0. | OWASP/ | 187 | — | ~835 | Automated safety check: Notes | Unknown | 13 days ago |
Questions, answered from the data.
What is the best skill in OWASP/secure-agent-playbook?
Prd Securability Enhancement from OWASP/secure-agent-playbook ranks first of the 14 skills in OWASP/secure-agent-playbook listed here, with the highest score: its repository has 187 GitHub stars, its SKILL.md loads about 4.6k tokens and it passes the automated safety check with no findings. Next come Securability Engineering Review and Securability Engineering.
Are the skills in OWASP/secure-agent-playbook official?
None yet. All 14 skills in OWASP/secure-agent-playbook listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from OWASP/secure-agent-playbook?
Run npx skills add OWASP/secure-agent-playbook in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.