mcpbeat Sign in

Common Owasp Agent Skill

OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.

4k tokens
context cost
the whole folder, loaded on every use
4
files
instructions only
0
copies elsewhere
how many repositories repackaged it
536
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/HoangNguyen0403/agent-skills-standard --skill common-owasp

What comes with it

12 101 bytes besides the instruction
references/owasp-api.md
references/owasp-mobile.md
references/owasp-web.md

The instruction itself

10 sections, as written by the author

OWASP Top 10 Security Checklist

Priority: P0 (CRITICAL)

Always-Apply Rules

Apply these on every code write, not during dedicated security reviews:

  • No IDOR: Filter every resource query by owner_id or tenantId alongside any user-supplied ID. findById(params.id) without owner filter immediate P0.
  • No wildcard CORS: Restrict to explicit allowlisted origins — never Access-Control-Allow-Origin: * on authenticated routes.
  • No full entity return: Always project to DTO — never serialize raw ORM output to API response.
  • No plaintext secrets in mobile: Never store tokens in SharedPreferences/UserDefaults — use Keychain/Keystore.

Context-Specific Checklist

Activate when: writing security-sensitive features, reviewing PRs, or doing codebase audits.

Mark each item: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.

P0 finding caps Security score at 40/100.

Apply framework-specific security skills alongside this checklist.

See references/owasp-web.md, references/owasp-api.md, and references/owasp-mobile.md for full detection signals.

OWASP Web Application Top 10 (2021)

| ID | Risk | Key Detection Signal |

| --- | ---- | -------------------- |

| A01 | Broken Access Control | findById(params.id) without owner filter. Route without @authorize. |

| A02 | Cryptographic Failures | Weak hash (MD5/SHA1) for passwords. HTTP URL hardcoded. No TLS. |

| A03 | Injection | String concat in DB queries. Unsanitized input to templates. XSS. |

| A04 | Insecure Design | No rate limiting on auth. Missing input validation at entry points. |

| A05 | Security Misconfiguration | CORS *. Debug mode in prod. Missing security headers (CSP, HSTS). |

| A06 | Vulnerable Components | CVE in dependency audit. Unreviewed new direct dependency. |

| A07 | Auth Failures | JWT without expiry. No session invalidation on logout. |

| A08 | Data Integrity Failures | Unverified JWT/cookie. Deserialization of untrusted input. |

| A09 | Logging & Monitoring | No audit log on: deletion, password change, privilege escalation. |

| A10 | SSRF | HTTP client with user-controlled URL and no allowlist. |

OWASP API Security Top 10 (2023)

| ID | Risk | Key Detection Signal |

| ----- | ---- | -------------------- |

| API1 | Broken Object Level Auth (BOLA) | Resource by user-supplied ID without AND owner_id = currentUser. |

| API2 | Broken Authentication | JWT missing exp. Token not revoked on logout. Bearer in URL. |

| API3 | Broken Property Level Auth | Full ORM entity returned. No DTO projection. Mass assignment. |

| API4 | Unrestricted Resource Consumption | No server-enforced limit/pageSize. No throttle on heavy ops. |

| API5 | Broken Function Level Auth | Admin route reachable without role guard. |

| API6 | Unrestricted Business Flow | No verification on OTP/checkout/password-reset flows. |

| API8 | Security Misconfiguration | Stack trace in response. CORS * on authenticated routes. |

| API9 | Improper Inventory Management | Deprecated/undocumented endpoints still reachable. |

| API10 | Unsafe API Consumption | Third-party response used without schema validation. |

OWASP Mobile Top 10 (2024)

| ID | Risk | Key Detection Signal |

| --- | ---- | -------------------- |

| M1 | Improper Credential Usage | API keys in BuildConfig, Info.plist, hardcoded in source. |

| M2 | Inadequate Supply Chain | Unverified SDKs, pods, or packages without lock files. |

| M3 | Insecure Auth/AuthZ | Biometric-only auth without server validation. Local role checks. |

| M4 | Insufficient I/O Validation | WebView loadUrl with user data. Intent data used unvalidated. |

| M5 | Insecure Communication | No cert pinning. cleartextTrafficPermitted=true. ATS exceptions. |

| M6 | Inadequate Privacy | Location/contacts without justification. PII in analytics. |

| M7 | Insufficient Binary Protection | No obfuscation. android:debuggable=true. No root detection. |

| M8 | Security Misconfiguration | Exported components. Backup enabled. Debug endpoints. |

| M9 | Insecure Data Storage | Tokens in SharedPreferences/UserDefaults vs Keychain/Keystore. |

| M10 | Insufficient Cryptography | Hardcoded encryption keys. Deprecated algorithms (DES, RC4). |

References

  • OWASP Web App — Full Detection Signals
  • OWASP API — Full Detection Signals
  • OWASP Mobile — Full Detection Signals

Canonical response anchors

  • Additional task-grounded exact anchors: rate limit, IDOR/BOLA, DTO projection

Remediation anchors

  • Remediation anchors: DTO projection, CORS, opaque session, JWT expiry, rate limiting

Other skills for the same job

different authors, same section of the catalogue
Codebase Cleanup Deps Audit
by ComeOnOliver
×2

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

10k tokens
Security Best Practices
by openai
vendor ×1

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

103k tokens
Better Auth
by mrgoonie
×1

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

46k tokens scripts
Repomix
by mrgoonie
×1

Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.

27k tokens scripts
Dependency Management Deps Audit
by lingxling
×1

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

7k tokens
Hubspot Integration
by lingxling
×1

Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.

5k tokens
Security Best Practices
by christophacham
×1

Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.

102k tokens
API Gateway Configuration
by ComeOnOliver
×1

Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.

525 tokens

How to use it

Copy the folder

Take hoangnguyen0403/common-owasp from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.