Senior Secops
alirezarezvani/claude-skills
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .claude/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .claude/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .agents/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .agents/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .cursor/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .cursor/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/mapping-findings-to-owasp-top10--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .gemini/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .gemini/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .github/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .github/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace mapping-findings-to-owasp-top10 --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/mapping-findings-to-owasp-top10 .opencode/skills/mapping-findings-to-owasp-top10 && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mapping-findings-to-owasp-top10" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/mapping-findings-to-owasp-top10 into .opencode/skills/mapping-findings-to-owasp-top10/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mapping-findings-to-owasp-top10", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mapping-findings-to-owasp-top10Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.
Mapping Findings To Owasp Top10 is an agent skill from jeremylongshore/tons-of-skills-marketplace. Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. Produces an enriched findings JSONL plus a per-category rollup report showing how findings distribute across A01 through A10. Required for customer-facing OWASP coverage sections and compliance contexts (PCI DSS 6.5, SOC2 CC7, ISO 27001 A.14.2). Use when: enriching findings after cluster 1-4 scans, regenerating the…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/map_owasp.py`). Compatibility notes: Designed for Claude Code
It sits in Security, covering Web application vulnerabilities and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteBash(python3:*)GlobFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Mapping Findings To Owasp Top10 loads about 2.1k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 218 tokens; SKILL.md has 692 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Write(.env)- Edit(.env)detail_contains: ".env"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 692 words, ~2,074 tokens.
.claude/skills/mapping-findings-to-owasp-top10/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.OWASP Top 10 is the canonical taxonomy of web-application risk categories. Every customer-facing pentest report has an "OWASP coverage" section because customers, auditors, and insurers expect to see findings mapped against the Top 10. Without the mapping, a long list of CVEs and misconfigurations reads as noise; with the mapping, it reads as a structured assessment.
This skill applies a deterministic rule table to annotate each finding with its OWASP category. Rules are keyed on:
auditing-npm-dependencies
is almost always A06 — Vulnerable and Outdated Components).dependency-vulnerability, engagement-scope).Output is an enriched JSONL (each finding gets an owasp_category
field) plus a coverage report showing how the engagement's
findings distribute across A01-A10. UNMAPPED findings are
surfaced for human review — extend the rule table or accept the
finding as cross-cutting (some findings genuinely don't fit a
single A0X bucket).
| Finding | Severity | Threshold | Affected control |
|---|---|---|---|
| Finding unmapped after rule application | INFO | No rule matched the finding | (operational) |
| Source JSONL unparseable | HIGH | Standard JSONL parse error | (operational) |
| Annotation written back successfully | INFO | Confirmation per source file | (informational) |
| Coverage report generated | INFO | Coverage report path emitted | (informational) |
| Engagement covers all 10 categories | INFO | At least one finding in each A01-A10 bucket | (positive observation) |
| Engagement covers <5 of 10 categories | MEDIUM | Suggests scope may have been narrow | (informational) |
| Category | Description |
|---|---|
| A01:2021 | Broken Access Control |
| A02:2021 | Cryptographic Failures |
| A03:2021 | Injection |
| A04:2021 | Insecure Design |
| A05:2021 | Security Misconfiguration |
| A06:2021 | Vulnerable and Outdated Components |
| A07:2021 | Identification and Authentication Failures |
| A08:2021 | Software and Data Integrity Failures |
| A09:2021 | Security Logging and Monitoring Failures |
| A10:2021 | Server-Side Request Forgery |
.owasp-overrides.yaml for engagement-specific
classification rulesDefault: every file under engagement/findings/*.json[l].
Override with --source FILE (repeatable).
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/Options:
Usage: map_owasp.py PATH [OPTIONS]
Options:
--source FILE Specific findings file (repeatable)
--enrich-output FILE Write annotated findings JSONL here
(default: PATH/findings/all-with-owasp.jsonl)
--coverage-output FILE Coverage report path
(default: PATH/reports/owasp-coverage.md)
--overrides FILE Optional rule-overrides YAML
--output FILE Operational findings output
--format FMT json | jsonl | markdown (default: markdown)
--min-severity SEV default infoUNMAPPED findings are surfaced as INFO. For each:
The coverage report lists each A0X category with:
For an engagement intended as broad-coverage testing, all ten categories should have at least one entry. Categories with zero findings either reflect scope ("we didn't test for this") or clean results ("we tested and found nothing").
python3 ./scripts/map_owasp.py engagements/acme-2026-q2/Produces engagements/acme-2026-q2/findings/all-with-owasp.jsonl
(enriched findings) and engagements/acme-2026-q2/reports/owasp-coverage.md
(coverage report).
# .owasp-overrides.yaml — engagement-specific classifications
- skill_id: auditing-cors-policy
owasp_category: A05:2021 — Security Misconfiguration
reason: customer treats CORS as misconfig, not access-control
- skill_id: scanning-for-hardcoded-secrets
detail_contains: ".env"
owasp_category: A02:2021 — Cryptographic Failures
reason: env-file leaks treated as crypto failure for this engagementpython3 ./scripts/map_owasp.py engagements/acme-2026-q2/ \
--overrides engagements/acme-2026-q2/.owasp-overrides.yamlpython3 ./scripts/map_owasp.py engagements/acme-2026-q2/ \
--enrich-output /dev/null \
--coverage-output /tmp/coverage.mdProduces the coverage report without modifying findings files.
JSON / JSONL / Markdown per lib/report.py for operational
findings. PRIMARY outputs:
--enrich-output — every
finding from the sources has an owasp_category field added.--coverage-output — per-
category rollup.Each operational Finding includes:
id — owasp::<issue>::<finding-fingerprint>severity — INFO mostly; HIGH for parse errorscategory — owasp-mappingsummary — what happened to the findingevidence — original finding fingerprint, derived OWASP
category, rule that matchedreferences/THEORY.md — OWASP Top 10 history and 2021 changes,
CWE → OWASP cross-walk, rule-table design rationale, when a
finding genuinely doesn't fit, OWASP A0X precision tradeoffs
(broad categories vs specific findings)references/PLAYBOOK.md — Default rule table per cluster 1-4
skill, override YAML format, coverage-audit interpretation,
customer-specific category preferences, integration with
PCI DSS 6.5 / NIST 800-53 control mapping© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/.curated/mapping-findings-to-owasp-top10 of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Mapping Findings To Owasp Top10 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mapping Findings To Owasp Top10 this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | |
| Senior Secopsalirezarezvani/claude-skills | 28k | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Security Auditoraiskillstore/marketplace | 433 | 6 repos | ~2.6k | Automated safety check: Pass | None | |
| Agent Bom ComplianceLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Security Auditorcuriositech/some_claude_skills | 244 | — | ~2.2k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.
mukul975/Anthropic-Cybersecurity-Skills
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.
aiskillstore/marketplace
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
LeoYeAI/openclaw-master-skills
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.
curiositech/some_claude_skills
Security vulnerability scanner and OWASP compliance auditor for codebases.
dralgorhythm/claude-agentic-framework
Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. Mapping Findings To Owasp Top10 is an agent skill from jeremylongshore/tons-of-skills-marketplace. Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.
Mapping Findings To Owasp Top10 fits situations like: : enriching findings after cluster 1-4 scans; regenerating the report with OWASP tags; producing the OWASP coverage section for an exec summary; auditing engagement OWASP coverage.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a claude-code`. Or copy the skill folder (skills/.curated/mapping-findings-to-owasp-top10 in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/mapping-findings-to-owasp-top10 in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a codex`. Or copy the skill folder (skills/.curated/mapping-findings-to-owasp-top10 in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/mapping-findings-to-owasp-top10 in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill mapping-findings-to-owasp-top10 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mapping-findings-to-owasp-top10, .gemini/skills/mapping-findings-to-owasp-top10, .github/skills/mapping-findings-to-owasp-top10 and .opencode/skills/mapping-findings-to-owasp-top10 in your project.
Going by SKILL.md and its folder, Mapping Findings To Owasp Top10 needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Mapping Findings To Owasp Top10 is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Mapping Findings To Owasp Top10: Senior Secops (alirezarezvani/claude-skills, 28k stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security Auditor (aiskillstore/marketplace, 433 stars) and Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.