Ralph Tui Create Beads
subsy/ralph-tui
Convert PRDs to beads for ralph-tui execution. An agent skill from subsy/ralph-tui.
Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancement --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .claude/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .claude/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancement --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .agents/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .agents/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancement --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .cursor/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .cursor/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OWASP/secure-agent-playbook.git --path plugins/code-security-skills/skills/prd-securability-enhancement--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancement --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .gemini/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .gemini/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .github/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .github/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OWASP/secure-agent-playbook prd-securability-enhancement --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/code-security-skills/skills/prd-securability-enhancement .opencode/skills/prd-securability-enhancement && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "prd-securability-enhancement" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/prd-securability-enhancement into .opencode/skills/prd-securability-enhancement/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prd-securability-enhancement", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
prd-securability-enhancementEnhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.
Prd Securability Enhancement is an agent skill from OWASP/secure-agent-playbook. Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written. Trigger on "harden the PRD/spec", "choose ASVS level", "map features to ASVS", "find missing security requirements", "add NFRs for security", "make these requirements securable", "security-review my product brief". For code review use securability-engineering-review; for code generation use securability-engineering.
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Product & Project Management, covering PRD writing and User stories. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Prd Securability Enhancement loads about 4.6k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,783 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 1,783 words, ~4,614 tokens.
.claude/skills/prd-securability-enhancement/SKILL.md (or your agent's skills folder).Enhance PRD content so each feature has explicit, testable securability requirements aligned to OWASP ASVS and shaped by FIASSE v1.0.4 / SSEM. The goal is to upgrade the requirements artifact before implementation, so delivery teams build securable capabilities by design rather than retrofitting controls later.
This skill is requirements-centric. It does not review or write code. If the user wants code review, redirect to securability-engineering-review. If they want code generation, redirect to securability-engineering.
Trigger this skill when the user asks to:
Adjacent phrasings: "security-review this spec", "what's missing security-wise from this feature list", "add NFRs for security to my PRD", "make these requirements securable".
Ask the user for whatever is missing before starting:
If the artifact is large, parse the features inline; do not require the user to pre-extract them.
Extract each feature into a normalized record. Capture for each:
F-01 if absent)If the source PRD lumps several capabilities into one bullet, split them so each feature is independently testable.
Selecting the level before mapping requirements prevents both under-scoping and over-scoping. Use this rubric:
| Level | Use when |
|---|---|
| 1 | Internal tooling, prototypes, low-sensitivity data, no regulatory pressure, limited blast radius if compromised |
| 2 | Typical production web/API systems with authenticated users, business-critical behavior, customer data, or moderate regulatory exposure (most products land here) |
| 3 | High-assurance contexts: payments, health records, government, identity providers, anything where compromise causes severe material impact or where attackers are well-resourced |
Default to Level 2 unless evidence pushes lower or higher. Document:
For every feature, use data/asvs/README.md (chapter index) and the when_to_use frontmatter in data/asvs/V*.md to identify applicable chapters. Common mappings:
Filter requirements by the chosen ASVS level. For each requirement, classify coverage:
Use the ASVS Coverage Gap Pattern Table below to spot the gaps that PRDs reliably miss.
Write a short paragraph per feature surfacing only the SSEM and FIASSE points that materially shape implementation. Do not enumerate all ten SSEM attributes or all FIASSE tenets — that produces noise.
Useful lenses (mention only when relevant):
For each added or strengthened requirement, write at least one acceptance criterion that is:
Ambiguous "secure" or "robust" language is not acceptable here.
Produce these sections in order, using the exact templates below.
These are the gaps PRDs reliably miss. When you see one of the trigger phrasings on the left, add the named requirements on the right — they are almost always missing in the source artifact.
| PRD trigger phrasing (what the feature says) | Almost-always-missing requirements | ASVS section | Tag |
|---|---|---|---|
| "User logs in with email and password" | Account-enumeration parity (same response/timing for valid vs invalid email); password-screen against breached-password list; auth-event audit log; per-account brute-force rate limit | V6.3.8, V2.1, V2.4, V16.3 | "Auth surface gaps" |
| "User resets/forgets password" | Account-enumeration parity on the request endpoint; single-use token; short expiry (≤15 min); token-hash-at-rest; rate-limit per email and per IP; audit log of issuance/redemption | V6.3.8, V6.2, V2.4, V16.3 | "Reset flow gaps" |
| "User uploads a file" | Type allow-list (not deny-list); content-sniffing vs declared type; max size; antivirus/safe-storage path; filename canonicalization; storage outside web root; URL non-guessability | V5.1, V5.2, V12.1 | "Upload gaps" |
| "User can edit their profile" / "update settings" | Allow-listed mutable fields (no email/role/is_admin from request body); ownership check on the resource; audit log of changes; old-vs-new value capture | V4.1, V4.2, V16.2, V16.3 | "Mass-assignment gaps" |
| "Admin can do X" / "role-based access" | Authorization decision logged with grant/deny; centralized authz module (not scattered checks); deny-by-default at boundary; ownership scoping on every record fetch | V4.1, V4.2, V16.2, V16.3 | "Authz gap" |
| "Public API endpoint" / "third-party integration" | Per-key/per-client rate limits; auth for every call (not first-call only); request-id propagation; response field allow-list (no leaking internal fields); contract validation | V2.4, V9.1, V13.1, V16.2 | "API gaps" |
| "Send email/SMS to user" | Templated payload with no user-controlled subject/body injection; rate-limit per recipient and per actor; bounce/abuse-loop handling; opt-out and audit log | V2.4, V12.1, V13.1, V16.3 | "Outbound-message gaps" |
| "Search / filter / list with user-supplied parameters" | Parameter allow-list; ordering/pagination caps; query timeout; result count cap; tenant/owner scoping enforced server-side | V4.1, V12.1, V13.1 | "Query-surface gaps" |
| "Webhook receiver" / "callback URL" | Source verification (signature, mTLS, IP allow-list); replay protection (timestamp + nonce); idempotency key; rate-limit; audit log of received events | V2.4, V2.5, V9.1, V16.3 | "Webhook gaps" |
| "Save user file/document/note" | Owner identifier never client-supplied; size and content caps; rich-text/HTML sanitization on read or write; audit log of writes | V4.1, V5.1, V12.1, V16.3 | "Server-owned state gaps (Derived Integrity)" |
| "Export data" / "download report" | Authorization re-checked on export (not just on UI route); rate-limit; audit log including row count; PII-scrub policy if applicable | V4.1, V7.1.1, V8.1 | "Export gaps" |
| "Background job processes user-submitted data" | Same boundary discipline as the synchronous path (validation, surface minimization, owner scoping); job-level audit log; poison-message handling and DLQ | V11.1, V12.1, V7.1.1 | "Async-path boundary gaps" |
| "Configuration / feature flag / admin setting" | Change requires authenticated actor and audit record; cannot be set via product API without admin role; secret values never echoed back; defaults are safe | V7.1.1, V10.1, V14.2 | "Config-surface gaps" |
| "PII/PHI/financial data" mentioned anywhere | Field-level classification; encryption at rest and in transit; retention/disposal policy; access-log requirement; export/erasure (right-to-be-forgotten) flows | V8.1, V14.1 | "Sensitive-data lifecycle gaps" |
| "Real-time" / "websocket" / "streaming" feature | Per-connection auth (not just first message); per-connection resource caps; back-pressure / max-queue; idle timeout; audit of connection lifecycle | V3.1, V9.1, V11.1.4 | "Streaming gaps" |
| "AI/LLM-backed feature" | Prompt-injection handling at trust boundary; output validation before downstream side effects; per-actor rate limit and cost cap; audit log of prompts and tool calls; PII redaction policy | V11.1, V12.1, V8.1 | "LLM boundary gaps" |
When a feature triggers one of these patterns, prefill the corresponding requirements as Missing in the coverage matrix unless the PRD explicitly addresses them — most of the time it doesn't.
## ASVS Level Decision
**Chosen Level**: [1 | 2 | 3]
**Rationale**: [2–4 sentences. Cover data sensitivity, user population, regulatory context, and material-impact reasoning. Note why lower levels are insufficient if Level > 1.]
**Feature-Level Escalations**: [List any features that need a higher level than baseline, with one-line justification, or "None".]## Feature ↔ ASVS Coverage Matrix
| Feature | ASVS Section | Requirement ID | Level | Coverage | PRD Change Needed |
|---------|--------------|----------------|-------|----------|-------------------|
| F-01 | V2.2 | 2.2.1 | 2 | Missing | Add MFA requirement for high-risk actions |
| F-01 | V7.1 | 7.1.1 | 2 | Partial | Specify which auth events are logged |
| F-02 | V12.1 | 12.1.1 | 2 | Covered | — |Aim for completeness over brevity here — every feature × every applicable requirement gets a row. Where the gap pattern table applies, include the named requirements it surfaces.
For each feature, emit exactly this shape:
### Feature F-01: [Title]
**Actor**: [user role / system]
**Data**: [data classes touched]
**Trust Boundaries**: [boundaries crossed]
**ASVS Mapping**: V2.2.1, V7.1.1, ...
**Updated Requirements**:
- [Original requirement, kept or rewritten]
- [Newly added requirement from ASVS mapping]
- [Newly added requirement from ASVS mapping]
**Acceptance Criteria**:
- [Testable criterion tied to a requirement above]
- [Testable criterion tied to a requirement above]
**Securability Notes**: [Short paragraph — only material SSEM/FIASSE points for this feature. Do not enumerate all attributes.]Controls that span multiple features (centralized logging, secrets management, dependency policy, baseline TLS, error-handling standards). One bullet each, with the ASVS reference.
Anything you could not resolve from the input: missing system context, unclear data sensitivity, unstated user populations, deferred decisions. Be explicit so the team can close these before implementation.
Input feature (from a PRD):
F-03: Users can reset their password by clicking "Forgot Password" and entering their email. The system emails a reset link.
This trips the "Reset flow gaps" pattern in the gap table — so the missing requirements are predictable.
Enhanced output:
### Feature F-03: Password Reset via Email
**Actor**: Unauthenticated user (claiming an account)
**Data**: Email address (PII), password (credential), reset token
**Trust Boundaries**: browser → public API; API → email provider; API → credential store
**ASVS Mapping**: V2.2.2, V6.2.1, V6.2.2, V7.1.1, V11.1.4, V12.1.1
**Updated Requirements**:
- User can request a password reset by entering an account email at `/reset`.
- The system always returns the same success response whether or not the email matches an account (prevents account enumeration, V2.2.2).
- Reset tokens are single-use, expire within 15 minutes, and are stored only as a salted hash (V6.2).
- New passwords are validated against a minimum policy and screened against a known-breached-password list (V6.2.1).
- All reset requests, token issuances, token redemptions, and password changes are logged with user ID, source IP, user agent, and outcome (V7.1.1).
- Reset requests are rate-limited per email and per source IP (V11.1.4).
- The email input is canonicalized and validated against a strict format (V12.1.1).
**Acceptance Criteria**:
- Submitting a non-existent email returns the same response body, status code, and timing characteristics as a valid email (within tolerance).
- A reset token cannot be redeemed after 15 minutes or after first successful use; both cases produce a generic failure response and a logged `reset_token_invalid` event.
- More than 5 reset requests for the same email within 10 minutes are rejected with HTTP 429 and logged.
- Audit log lines for reset events are queryable by user ID and contain the fields above.
**Securability Notes**: This feature crosses an unauthenticated trust boundary (FIASSE v1.0.4 S4.3), so input handling and rate limiting are the load-bearing concerns. The reset token is server-owned state; never accept client-supplied token attributes beyond the opaque token itself (Derived Integrity, FIASSE v1.0.4 S4.4.1.2). Centralize token generation, hashing, and verification in a single module so the policy can evolve without touching call sites (Modifiability). All reset events must be observable in the audit pipeline so abuse patterns can be detected (Accountability + Observability, FIASSE v1.0.4 S3.2.1.4; Transparency S2.5).This is the level of specificity the output should hit — concrete, testable, and traceable back to ASVS.
Coverage
Output discipline
Traceability
data/asvs/README.mddata/asvs/V*.mddata/fiasse/S2.1.md–S2.6.md (Transparency S2.5, Least Astonishment S2.6)data/fiasse/S3.2.1.md–S3.2.3.md; leaf files (e.g. S3.2.1.4.md Observability) for attribute-specific guidancedata/fiasse/S4.3.md, S4.4.md, and the canonical-input-handling leaves S4.4.1.md, S4.4.1.1.md, S4.4.1.2.mddata/fiasse/S4.5.md, S4.6.md© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/code-security-skills/skills/prd-securability-enhancement of OWASP/secure-agent-playbook.
Open the folder on GitHubat commit 1b5fd4c
Prd Securability Enhancement next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Prd Securability Enhancement this skillOWASP/secure-agent-playbook | 187 | — | ~4.6k | Automated safety check: Pass | CC-BY-4.0 | |
| Ralph Tui Create Beadssubsy/ralph-tui | 2.5k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Ralph Tui Create Beads Rustsubsy/ralph-tui | 2.5k | 1 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Ralph Tui Create JSONsubsy/ralph-tui | 2.5k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| To Prdywwynm/EverythingDone | 144 | 11 repos | ~777 | Automated safety check: Pass | GPL-3.0 | |
| Use Case Writerphucnt-bazone-vietnam/use-case-writer | 142 | — | ~4.1k | Automated safety check: Pass | MIT |
subsy/ralph-tui
Convert PRDs to beads for ralph-tui execution. An agent skill from subsy/ralph-tui.
subsy/ralph-tui
Convert PRDs to beads for ralph-tui execution using beads-rust (br CLI).
subsy/ralph-tui
Convert PRDs to prd.json format for ralph-tui execution. An agent skill from subsy/ralph-tui.
ywwynm/EverythingDone
Turn the current conversation context into a PRD and publish it to the project issue tracker.
phucnt-bazone-vietnam/use-case-writer
Generate Use Case specifications in English Markdown following the IT BA standard 13-field template (Karl Wiegers / IIBA).
adrianpuiu/claude-skills-marketplace
Comprehensive project planning and documentation generator for software projects.
OWASP/secure-agent-playbook
Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…
OWASP/secure-agent-playbook
Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…
OWASP/secure-agent-playbook
Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.
OWASP/secure-agent-playbook
Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.
OWASP/secure-agent-playbook
Comprehensive API security review against OWASP API Security Top 10 (2023).
OWASP/secure-agent-playbook
Security-focused code review mapped to OWASP Top 10 and ASVS.
Categories
Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written. Prd Securability Enhancement is an agent skill from OWASP/secure-agent-playbook.4 SSEM implementation guidance — before code is written.
Prd Securability Enhancement fits situations like: harden the PRD/spec; choose ASVS level; map features to ASVS; find missing security requirements.
Run `npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/prd-securability-enhancement in OWASP/secure-agent-playbook) into .claude/skills/prd-securability-enhancement in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/prd-securability-enhancement in OWASP/secure-agent-playbook) into .agents/skills/prd-securability-enhancement in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill prd-securability-enhancement -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prd-securability-enhancement, .gemini/skills/prd-securability-enhancement, .github/skills/prd-securability-enhancement and .opencode/skills/prd-securability-enhancement in your project.
SKILL.md names no scripts, command-line tools or credentials: Prd Securability Enhancement is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Prd Securability Enhancement is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Prd Securability Enhancement: Ralph Tui Create Beads (subsy/ralph-tui, 2.5k stars), Ralph Tui Create Beads Rust (subsy/ralph-tui, 2.5k stars), Ralph Tui Create JSON (subsy/ralph-tui, 2.5k stars) and To Prd (ywwynm/EverythingDone, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 187 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.
Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.