Agent skill

AI Security Verification

by OWASP in OWASP/secure-agent-playbook

Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

CC-BY-4.0Auto-check passedSecurity

Install AI Security Verification

skills CLI
$ npx skills add OWASP/secure-agent-playbook --skill ai-security-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OWASP/secure-agent-playbook ai-security-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-security-skills/skills/ai-security-verification .claude/skills/ai-security-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-security-verification
GitHub stars
187
Token cost
~876 tokens
SKILL.md length
332 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

  • Works in 12 steps: Training Data Governance & Bias… → User Input Validation — Evaluate input… → Model Lifecycle Management & Change… → …
  • Verifying an AI-driven application
  • SKILL.md covers Steps, Output and OWASP References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AI Security Verification is an agent skill from OWASP/secure-agent-playbook. Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. Use when verifying an AI-driven application, ML pipeline, or LLM-integrated system against AISVS, preparing for an AI security audit, or checking security and ethical controls across 13 categories from training data governance to human oversight.

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security and Web application vulnerabilities. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.

When your agent uses it

  • Verifying an AI-driven application
  • LLM-integrated system against AISVS
  • Preparing for an AI security audit
  • Checking security and ethical controls across 13 categories from training data governance to human oversight

Example prompts

  • “/ai-security-verification”

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. Training Data Governance & Bias Management — Assess data quality, provenance, bias detection, and governance controls throughout the data…
  2. User Input Validation — Evaluate input sanitization, prompt injection defenses, adversarial input detection, and boundary validation…
  3. Model Lifecycle Management & Change Control — Review model versioning, deployment controls, rollback capabilities, and change management…
  4. Infrastructure, Configuration & Deployment Security — Examine deployment security, container hardening, network controls, and…
  5. Access Control & Identity — Verify authentication mechanisms, authorization controls, privilege management, and identity governance.
  6. Supply Chain Security for Models, Frameworks & Data — Assess third-party model security, dependency management, and supply chain integrity.
  7. Model Behavior, Output Control & Safety Assurance — Evaluate output validation, safety guardrails, behavior monitoring, and harmful…
  8. Memory, Embeddings & Vector Database Security — Review vector database security, embedding protection, memory isolation, and context…
  9. Autonomous Orchestration & Agentic Action Security — Assess agent coordination security, tool access controls, and autonomous…
  10. Adversarial Robustness & Attack Resistance — Test resilience against adversarial examples, evasion attacks, and model extraction attempts.
  11. Privacy Protection & Personal Data Management — Verify privacy controls, data minimization, consent management, and regulatory compliance.
  12. Monitoring, Logging & Anomaly Detection — Evaluate security monitoring, audit logging, anomaly detection, and incident response…

What it can do on your machine

Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Security Verification loads about 876 tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~876

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 332 words, ~876 tokens.

Download SKILL.mdSave it as .claude/skills/ai-security-verification/SKILL.md (or your agent's skills folder).
name
ai-security-verification
description
Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. Use when verifying an AI-driven application, ML pipeline, or LLM-integrated system against AISVS, preparing for an AI security audit, or checking security and ethical controls across 13 categories from training data governance to human oversight.
license
CC-BY-4.0

AI Security Verification Standard (AISVS)

Conduct comprehensive security verification of AI-driven applications using the OWASP AI Security Verification Standard (AISVS) framework's 13-category structured checklist. Follow the full procedure in plays/ai-security-verification.md.

Steps

  1. Training Data Governance & Bias Management — Assess data quality, provenance, bias detection, and governance controls throughout the data lifecycle.

  2. User Input Validation — Evaluate input sanitization, prompt injection defenses, adversarial input detection, and boundary validation mechanisms.

  3. Model Lifecycle Management & Change Control — Review model versioning, deployment controls, rollback capabilities, and change management processes.

  4. Infrastructure, Configuration & Deployment Security — Examine deployment security, container hardening, network controls, and infrastructure configuration.

  5. Access Control & Identity — Verify authentication mechanisms, authorization controls, privilege management, and identity governance.

  6. Supply Chain Security for Models, Frameworks & Data — Assess third-party model security, dependency management, and supply chain integrity.

  7. Model Behavior, Output Control & Safety Assurance — Evaluate output validation, safety guardrails, behavior monitoring, and harmful content prevention.

  8. Memory, Embeddings & Vector Database Security — Review vector database security, embedding protection, memory isolation, and context management.

  9. Autonomous Orchestration & Agentic Action Security — Assess agent coordination security, tool access controls, and autonomous decision-making safeguards.

  10. Adversarial Robustness & Attack Resistance — Test resilience against adversarial examples, evasion attacks, and model extraction attempts.

  11. Privacy Protection & Personal Data Management — Verify privacy controls, data minimization, consent management, and regulatory compliance.

  12. Monitoring, Logging & Anomaly Detection — Evaluate security monitoring, audit logging, anomaly detection, and incident response capabilities.

  13. Human Oversight and Trust — Assess human-in-the-loop controls, explainability mechanisms, and trust calibration measures.

Output

Use the finding format from templates/finding.md. Produce:

  • AISVS Compliance Assessment — Verification status across all 13 categories
  • Security Control Evaluation — Detailed analysis of implemented controls
  • Gap Analysis — Missing or inadequate security measures
  • Risk-Based Prioritization — Critical findings requiring immediate attention
  • Compliance Roadmap — Structured plan to achieve AISVS compliance
  • Verification Evidence — Documentation supporting compliance claims

OWASP References

  • OWASP AI Security Verification Standard (AISVS)
  • OWASP Top 10 for LLM Applications 2025
  • OWASP AI Security and Privacy Guide
  • OWASP Application Security Verification Standard (ASVS)
  • OWASP AI Testing Guide
  • Full procedure: plays/ai-security-verification.md

© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ai-security-skills/skills/ai-security-verification of OWASP/secure-agent-playbook.

Open the folder on GitHubat commit 1b5fd4c

Compare with similar skills

AI Security Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Security Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Security Verification this skillOWASP/secure-agent-playbook187—~876Automated safety check: PassCC-BY-4.0
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Agent Tool Abuse DetectionTencent/AI-Infra-Guard6.8k—~1.5kAutomated safety check: NotesApache-2.0
Secureclawadversa-ai/secureclaw3471 repos~193Automated safety check: PassMIT
Csono-session/pstack135—~12kAutomated safety check: NotesMIT
AI LLM Agent Securityzhaji2333/CkSKILLS114—~4.7kAutomated safety check: WarnMIT

Similar skills

  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Agent Tool Abuse Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets.

    6.8k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check: notes
  • Secureclaw

    adversa-ai/secureclaw

    Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw.

    347 GitHub starsUsed in 1 repo~193 tokens
    SecurityAuto-check passed
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    135 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    114 GitHub stars~4.7k tokensUpdated 24 days ago
    SecurityAuto-check: warnings
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: warnings

More from OWASP/secure-agent-playbook

All 14 skills in this repo
  • Prd Securability Enhancement

    OWASP/secure-agent-playbook

    Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.

    187 GitHub stars~4.6k tokensUpdated 13 days ago
    Auto-check passed
  • Securability Engineering Review

    OWASP/secure-agent-playbook

    Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…

    187 GitHub stars~4.6k tokensUpdated 13 days ago
    Auto-check passed
  • Securability Engineering

    OWASP/secure-agent-playbook

    Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…

    187 GitHub stars~5.8k tokensUpdated 13 days ago
    Auto-check passed
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    187 GitHub stars~542 tokensUpdated 13 days ago
    Auto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    187 GitHub stars~744 tokensUpdated 13 days ago
    Auto-check passed
  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    187 GitHub stars~549 tokensUpdated 13 days ago
    Auto-check passed

Categories

Questions about AI Security Verification

What does AI Security Verification do?

Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. AI Security Verification is an agent skill from OWASP/secure-agent-playbook. Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

When should I use AI Security Verification?

AI Security Verification fits situations like: verifying an AI-driven application; LLM-integrated system against AISVS; preparing for an AI security audit; checking security and ethical controls across 13 categories from training data governance to human oversight.

How do I install AI Security Verification in Claude Code?

Run `npx skills add OWASP/secure-agent-playbook --skill ai-security-verification -a claude-code`. Or copy the skill folder (plugins/ai-security-skills/skills/ai-security-verification in OWASP/secure-agent-playbook) into .claude/skills/ai-security-verification in your project. Claude Code loads it when a task matches its description.

How do I install AI Security Verification in Codex?

Run `npx skills add OWASP/secure-agent-playbook --skill ai-security-verification -a codex`. Or copy the skill folder (plugins/ai-security-skills/skills/ai-security-verification in OWASP/secure-agent-playbook) into .agents/skills/ai-security-verification in your project. Codex loads it when a task matches its description.

Can I use AI Security Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill ai-security-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-security-verification, .gemini/skills/ai-security-verification, .github/skills/ai-security-verification and .opencode/skills/ai-security-verification in your project.

What does AI Security Verification need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Security Verification is instructions for the agent only.

Does AI Security Verification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Security Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Security Verification use?

AI Security Verification is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Security Verification use?

About 876 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Security Verification?

Skills that share tags, products or a category with AI Security Verification: Sail (pillar-labs/sail-skill, 113 stars), Agent Tool Abuse Detection (Tencent/AI-Infra-Guard, 6.8k stars), Secureclaw (adversa-ai/secureclaw, 347 stars) and Cso (no-session/pstack, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Security Verification?

OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 187 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.

Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.