Agent skill

Agent Security Audit

by OWASP in OWASP/secure-agent-playbook

Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

CC-BY-4.0Auto-check passedSecurity

Install Agent Security Audit

skills CLI
$ npx skills add OWASP/secure-agent-playbook --skill agent-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OWASP/secure-agent-playbook agent-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-security-skills/skills/agent-security-audit .claude/skills/agent-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-security-audit
GitHub stars
186
Token cost
~542 tokens
SKILL.md length
234 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

  • Works in 6 steps: Permission Inventory — Enumerate every… → Prompt Injection Surface Analysis — For… → Excessive Agency Assessment (OWASP… → …
  • Reviewing CLAUDE.md files
  • SKILL.md covers Steps, Output and OWASP References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Agent Security Audit is an agent skill from OWASP/secure-agent-playbook. Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. Use when reviewing CLAUDE.md files, MCP configs, agent orchestration code, or any AI agent setup.

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security. It works with Model Context Protocol. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.

When your agent uses it

  • Reviewing CLAUDE.md files
  • Agent orchestration code
  • Any AI agent setup

Example prompts

  • “/agent-security-audit”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Permission Inventory — Enumerate every tool, MCP server, file system path, network access, and credential the agent has. Flag capabilities…
  2. Prompt Injection Surface Analysis — For each input path (user messages, tool outputs, MCP resources, RAG documents), assess whether…
  3. Excessive Agency Assessment (OWASP LLM06) — Check whether destructive/irreversible actions require confirmation, whether access exceeds…
  4. Data Exfiltration Path Analysis — Map how sensitive data could leave the agent boundary: secrets passed to external tools, file contents…
  5. Tool-Call Injection Assessment — For each tool: can user-controlled input reach tool parameters unsanitized? Check for command injection…
  6. Guardrail Evaluation — Check for system prompt safety instructions, tool call confirmations, output filtering, rate limiting, audit…

What it can do on your machine

Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Security Audit loads about 542 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 234 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~542

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 234 words, ~542 tokens.

Download SKILL.mdSave it as .claude/skills/agent-security-audit/SKILL.md (or your agent's skills folder).
name
agent-security-audit
description
Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. Use when reviewing CLAUDE.md files, MCP configs, agent orchestration code, or any AI agent setup.
license
CC-BY-4.0

Agent Security Audit

Evaluate an AI agent's security posture by following the full procedure in plays/agent-security-audit.md.

Steps

  1. Permission Inventory — Enumerate every tool, MCP server, file system path, network access, and credential the agent has. Flag capabilities beyond what its stated purpose requires.

  2. Prompt Injection Surface Analysis — For each input path (user messages, tool outputs, MCP resources, RAG documents), assess whether crafted input could cause the agent to invoke unintended tools, override instructions, or exfiltrate data.

  3. Excessive Agency Assessment (OWASP LLM06) — Check whether destructive/irreversible actions require confirmation, whether access exceeds need, whether the agent can escalate its own privileges, and whether individually-safe tool calls can chain into harmful outcomes.

  4. Data Exfiltration Path Analysis — Map how sensitive data could leave the agent boundary: secrets passed to external tools, file contents in web requests, cross-MCP-server data forwarding, sensitive data in logs.

  5. Tool-Call Injection Assessment — For each tool: can user-controlled input reach tool parameters unsanitized? Check for command injection, path traversal, SSRF, and SQL injection through agent-constructed calls.

  6. Guardrail Evaluation — Check for system prompt safety instructions, tool call confirmations, output filtering, rate limiting, audit logging, and sandboxing.

Output

Use the finding format from templates/finding.md. Produce a Permission Summary table, Risk Findings, Injection Surface Map, and prioritized Recommendations.

OWASP References

  • LLM01: Prompt Injection
  • LLM02: Sensitive Information Disclosure
  • LLM05: Improper Output Handling
  • LLM06: Excessive Agency
  • LLM07: System Prompt Leakage
  • LLM08: Vector and Embedding Weaknesses

© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ai-security-skills/skills/agent-security-audit of OWASP/secure-agent-playbook.

Open the folder on GitHubat commit 1b5fd4c

Compare with similar skills

Agent Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Security Audit this skillOWASP/secure-agent-playbook186—~542Automated safety check: PassCC-BY-4.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Reins Runtime Securitypegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0
Security GuidejnMetaCode/shellward140—~644Automated safety check: WarnApache-2.0

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Reins Runtime Security

    pegasi-ai/reins

    Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

    392 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Security Guide

    jnMetaCode/shellward

    OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

    140 GitHub stars~644 tokensUpdated 9 days ago
    SecurityAuto-check: warnings
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated 2 days ago
    SecurityAuto-check: warnings

More from OWASP/secure-agent-playbook

All 14 skills in this repo
  • Prd Securability Enhancement

    OWASP/secure-agent-playbook

    Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.

    186 GitHub stars~4.6k tokensUpdated 12 days ago
    Auto-check passed
  • Securability Engineering Review

    OWASP/secure-agent-playbook

    Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…

    186 GitHub stars~4.6k tokensUpdated 12 days ago
    Auto-check passed
  • Securability Engineering

    OWASP/secure-agent-playbook

    Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…

    186 GitHub stars~5.8k tokensUpdated 12 days ago
    Auto-check passed
  • AI Security Verification

    OWASP/secure-agent-playbook

    Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

    186 GitHub stars~876 tokensUpdated 12 days ago
    Auto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    186 GitHub stars~744 tokensUpdated 12 days ago
    Auto-check passed
  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    186 GitHub stars~549 tokensUpdated 12 days ago
    Auto-check passed

Questions about Agent Security Audit

What does Agent Security Audit do?

Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. Agent Security Audit is an agent skill from OWASP/secure-agent-playbook. Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

When should I use Agent Security Audit?

Agent Security Audit fits situations like: reviewing CLAUDE.md files; agent orchestration code; any AI agent setup.

How do I install Agent Security Audit in Claude Code?

Run `npx skills add OWASP/secure-agent-playbook --skill agent-security-audit -a claude-code`. Or copy the skill folder (plugins/ai-security-skills/skills/agent-security-audit in OWASP/secure-agent-playbook) into .claude/skills/agent-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Agent Security Audit in Codex?

Run `npx skills add OWASP/secure-agent-playbook --skill agent-security-audit -a codex`. Or copy the skill folder (plugins/ai-security-skills/skills/agent-security-audit in OWASP/secure-agent-playbook) into .agents/skills/agent-security-audit in your project. Codex loads it when a task matches its description.

Can I use Agent Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill agent-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-security-audit, .gemini/skills/agent-security-audit, .github/skills/agent-security-audit and .opencode/skills/agent-security-audit in your project.

What does Agent Security Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Agent Security Audit is instructions for the agent only.

Does Agent Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Security Audit use?

Agent Security Audit is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Security Audit use?

About 542 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Security Audit?

Skills that share tags, products or a category with Agent Security Audit: Forensify (alexgreensh/repo-forensics, 187 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars), Skill Inspector (NVIDIA/SkillSpector, 20k stars) and Reins Runtime Security (pegasi-ai/reins, 392 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Security Audit?

OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 186 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.

Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.