Agent skill

Mapping Findings To Owasp Top10

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.

MITAuto-check: notesSecurity

Install Mapping Findings To Owasp Top10

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .claude/skills/mapping-findings-to-owasp-top10 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mapping-findings-to-owasp-top10
GitHub stars
2.8k
Token cost
~2.1k tokens
SKILL.md length
692 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.

  • Works in 4 steps: Identify findings sources → Run the mapper → Review unmapped findings → …
  • : enriching findings after cluster 1-4 scans
  • SKILL.md covers Overview, When the skill produces findings, OWASP Top 10 (2021) reference and Prerequisites, plus 5 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Mapping Findings To Owasp Top10 is an agent skill from jeremylongshore/tons-of-skills-marketplace. Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. Produces an enriched findings JSONL plus a per-category rollup report showing how findings distribute across A01 through A10. Required for customer-facing OWASP coverage sections and compliance contexts (PCI DSS 6.5, SOC2 CC7, ISO 27001 A.14.2). Use when: enriching findings after cluster 1-4 scans, regenerating the…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/map_owasp.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Web application vulnerabilities and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : enriching findings after cluster 1-4 scans
  • Regenerating the report with OWASP tags
  • Producing the OWASP coverage section for an exec summary
  • Auditing engagement OWASP coverage

Example prompts

  • “map to OWASP”
  • “owasp top 10 mapping”
  • “annotate owasp categories”
  • “/mapping-findings-to-owasp-top10”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Bash(python3:*), Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify findings sources
  2. Run the mapper
  3. Review unmapped findings
  4. Read the coverage report

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash(python3:*)
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Mapping Findings To Owasp Top10 loads about 2.1k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 218 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~218
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:27
    - Write(.env)
  • NoteMentions a .env fileSKILL.md:28
    - Edit(.env)
  • NoteMentions a .env fileSKILL.md:178
    detail_contains: ".env"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 692 words, ~2,074 tokens.

Download SKILL.mdSave it as .claude/skills/mapping-findings-to-owasp-top10/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
mapping-findings-to-owasp-top10
description
Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. Produces an enriched findings JSONL plus a per-category rollup report showing how findings distribute across A01 through A10. Required for customer-facing OWASP coverage sections and compliance contexts (PCI DSS 6.5, SOC2 CC7, ISO 27001 A.14.2). Use when: enriching findings after cluster 1-4 scans, regenerating the report with OWASP tags, producing the OWASP coverage section for an exec summary, or auditing engagement OWASP coverage. Threshold: unclassifiable findings emitted as INFO with UNMAPPED category for operator review. Trigger with: "map to OWASP", "owasp top 10 mapping", "annotate owasp categories", "owasp coverage check".
allowed-tools
Read, Write, Bash(python3:*), Glob
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*), Bash(wget:*), Write(.env), Edit(.env)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, reporting, owasp, top10, pentest

Mapping Findings to OWASP Top 10

Overview

OWASP Top 10 is the canonical taxonomy of web-application risk categories. Every customer-facing pentest report has an "OWASP coverage" section because customers, auditors, and insurers expect to see findings mapped against the Top 10. Without the mapping, a long list of CVEs and misconfigurations reads as noise; with the mapping, it reads as a structured assessment.

This skill applies a deterministic rule table to annotate each finding with its OWASP category. Rules are keyed on:

  1. Source skill ID (a finding from auditing-npm-dependencies is almost always A06 — Vulnerable and Outdated Components).
  2. Finding category (the per-skill category tag, e.g. dependency-vulnerability, engagement-scope).
  3. CWE identifier if present (CWE → OWASP is a well-trodden mapping; OWASP themselves publish the cross-walk).
  4. Detail keywords as a fallback when the above don't determine a category.

Output is an enriched JSONL (each finding gets an owasp_category field) plus a coverage report showing how the engagement's findings distribute across A01-A10. UNMAPPED findings are surfaced for human review — extend the rule table or accept the finding as cross-cutting (some findings genuinely don't fit a single A0X bucket).

When the skill produces findings

FindingSeverityThresholdAffected control
Finding unmapped after rule applicationINFONo rule matched the finding(operational)
Source JSONL unparseableHIGHStandard JSONL parse error(operational)
Annotation written back successfullyINFOConfirmation per source file(informational)
Coverage report generatedINFOCoverage report path emitted(informational)
Engagement covers all 10 categoriesINFOAt least one finding in each A01-A10 bucket(positive observation)
Engagement covers <5 of 10 categoriesMEDIUMSuggests scope may have been narrow(informational)

OWASP Top 10 (2021) reference

CategoryDescription
A01:2021Broken Access Control
A02:2021Cryptographic Failures
A03:2021Injection
A04:2021Insecure Design
A05:2021Security Misconfiguration
A06:2021Vulnerable and Outdated Components
A07:2021Identification and Authentication Failures
A08:2021Software and Data Integrity Failures
A09:2021Security Logging and Monitoring Failures
A10:2021Server-Side Request Forgery

Prerequisites

  • Python 3.9+
  • One or more cluster 1-4 findings files
  • Optional .owasp-overrides.yaml for engagement-specific classification rules

Instructions

Step 1 — Identify findings sources

Default: every file under engagement/findings/*.json[l]. Override with --source FILE (repeatable).

Step 2 — Run the mapper
bash
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/

Options:

Usage: map_owasp.py PATH [OPTIONS]

Options:
  --source FILE           Specific findings file (repeatable)
  --enrich-output FILE    Write annotated findings JSONL here
                          (default: PATH/findings/all-with-owasp.jsonl)
  --coverage-output FILE  Coverage report path
                          (default: PATH/reports/owasp-coverage.md)
  --overrides FILE        Optional rule-overrides YAML
  --output FILE           Operational findings output
  --format FMT            json | jsonl | markdown (default: markdown)
  --min-severity SEV      default info
Step 3 — Review unmapped findings

UNMAPPED findings are surfaced as INFO. For each:

  1. Check whether a CWE was present; if so, the canonical CWE → OWASP cross-walk should have caught it. Extend the rule table.
  2. Check whether the finding's source skill ID is in the rule table; if not, add a skill-level default.
  3. If the finding genuinely doesn't fit a single A0X bucket, accept UNMAPPED and document in the engagement notes.
Show full SKILL.md (267 more words)Show less
Step 4 — Read the coverage report

The coverage report lists each A0X category with:

  • Count of findings mapped to that category
  • Severity breakdown within the category
  • Pointer to specific findings

For an engagement intended as broad-coverage testing, all ten categories should have at least one entry. Categories with zero findings either reflect scope ("we didn't test for this") or clean results ("we tested and found nothing").

Examples

Example 1 — End-of-engagement enrichment
bash
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/

Produces engagements/acme-2026-q2/findings/all-with-owasp.jsonl (enriched findings) and engagements/acme-2026-q2/reports/owasp-coverage.md (coverage report).

Example 2 — Apply engagement-specific overrides
yaml
# .owasp-overrides.yaml — engagement-specific classifications
- skill_id: auditing-cors-policy
  owasp_category: A05:2021 — Security Misconfiguration
  reason: customer treats CORS as misconfig, not access-control
- skill_id: scanning-for-hardcoded-secrets
  detail_contains: ".env"
  owasp_category: A02:2021 — Cryptographic Failures
  reason: env-file leaks treated as crypto failure for this engagement
bash
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/ \
    --overrides engagements/acme-2026-q2/.owasp-overrides.yaml
Example 3 — Coverage audit (no enrichment write-back)
bash
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/ \
    --enrich-output /dev/null \
    --coverage-output /tmp/coverage.md

Produces the coverage report without modifying findings files.

Output

JSON / JSONL / Markdown per lib/report.py for operational findings. PRIMARY outputs:

  1. Enriched findings JSONL at --enrich-output — every finding from the sources has an owasp_category field added.
  2. Coverage report markdown at --coverage-output — per- category rollup.

Each operational Finding includes:

  • id — owasp::<issue>::<finding-fingerprint>
  • severity — INFO mostly; HIGH for parse errors
  • category — owasp-mapping
  • summary — what happened to the finding
  • evidence — original finding fingerprint, derived OWASP category, rule that matched

Error Handling

  • PATH missing → CRITICAL operational finding, exits 1.
  • Source file unparseable → HIGH op finding, skip file.
  • No sources found → HIGH op finding, exits 1.
  • Override YAML unparseable → HIGH op finding, falls back to default rules.
  • Enriched output path not writable → HIGH op finding, exits 1.

Resources

  • references/THEORY.md — OWASP Top 10 history and 2021 changes, CWE → OWASP cross-walk, rule-table design rationale, when a finding genuinely doesn't fit, OWASP A0X precision tradeoffs (broad categories vs specific findings)
  • references/PLAYBOOK.md — Default rule table per cluster 1-4 skill, override YAML format, coverage-audit interpretation, customer-specific category preferences, integration with PCI DSS 6.5 / NIST 800-53 control mapping

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/mapping-findings-to-owasp-top10 of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/map_owasp.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Mapping Findings To Owasp Top10 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mapping Findings To Owasp Top10 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mapping Findings To Owasp Top10 this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Security Auditoraiskillstore/marketplace4336 repos~2.6kAutomated safety check: PassNone
Agent Bom ComplianceLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
Security Auditorcuriositech/some_claude_skills244—~2.2kAutomated safety check: PassMIT

Similar skills

  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Implementing Devsecops Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    433 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Agent Bom Compliance

    LeoYeAI/openclaw-master-skills

    AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

    2.2k GitHub stars~1.9k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    244 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Auditor

    dralgorhythm/claude-agentic-framework

    Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

    125 GitHub stars~496 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Mapping Findings To Owasp Top10

What does Mapping Findings To Owasp Top10 do?

Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. Mapping Findings To Owasp Top10 is an agent skill from jeremylongshore/tons-of-skills-marketplace. Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.

When should I use Mapping Findings To Owasp Top10?

Mapping Findings To Owasp Top10 fits situations like: : enriching findings after cluster 1-4 scans; regenerating the report with OWASP tags; producing the OWASP coverage section for an exec summary; auditing engagement OWASP coverage.

How do I install Mapping Findings To Owasp Top10 in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a claude-code`. Or copy the skill folder (skills/.curated/mapping-findings-to-owasp-top10 in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/mapping-findings-to-owasp-top10 in your project. Claude Code loads it when a task matches its description.

How do I install Mapping Findings To Owasp Top10 in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a codex`. Or copy the skill folder (skills/.curated/mapping-findings-to-owasp-top10 in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/mapping-findings-to-owasp-top10 in your project. Codex loads it when a task matches its description.

Can I use Mapping Findings To Owasp Top10 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mapping-findings-to-owasp-top10, .gemini/skills/mapping-findings-to-owasp-top10, .github/skills/mapping-findings-to-owasp-top10 and .opencode/skills/mapping-findings-to-owasp-top10 in your project.

What does Mapping Findings To Owasp Top10 need to run?

Going by SKILL.md and its folder, Mapping Findings To Owasp Top10 needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Mapping Findings To Owasp Top10 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mapping Findings To Owasp Top10 safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Mapping Findings To Owasp Top10 use?

Mapping Findings To Owasp Top10 is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mapping Findings To Owasp Top10 use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Mapping Findings To Owasp Top10?

Skills that share tags, products or a category with Mapping Findings To Owasp Top10: Senior Secops (alirezarezvani/claude-skills, 28k stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security Auditor (aiskillstore/marketplace, 433 stars) and Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mapping Findings To Owasp Top10?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.