mcpbeat

Owasp Infrastructure

microsoft/owasp-infrastructure

OWASP Infrastructure Top 10 knowledge base for identifying, assessing, and remediating internal IT infrastructure security risks.

12k tokens
context cost
the whole folder, loaded on every use
12
files
instructions only
0
copies elsewhere
how many repositories repackaged it
1313
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/microsoft/hve-core --skill owasp-infrastructure

What comes with it

46 468 bytes besides the instruction
references/00-vulnerability-index.md
references/01-outdated-software.md
references/02-insufficient-threat-detection.md
references/03-insecure-configurations.md
references/04-insecure-resource-user-management.md
references/05-insecure-use-of-cryptography.md
references/06-insecure-network-access-management.md
references/07-insecure-authentication-default-credentials.md
references/08-information-leakage.md
references/09-insecure-access-resources-management-components.md
references/10-insufficient-asset-management-documentation.md

The instruction itself

3 sections, as written by the author

OWASP Infrastructure Top 10 — Skill Entry

This SKILL.md is the entrypoint for the OWASP Infrastructure Top 10 skill.

The skill encodes the OWASP Infrastructure Security Top 10 (2024) as structured,

machine-readable references that an agent can query to identify, assess, and remediate

infrastructure security risks.

Normative references (Infrastructure Top 10)

  • 00 Vulnerability Index
  • 01 Outdated Software
  • 02 Insufficient Threat Detection
  • 03 Insecure Configurations
  • 04 Insecure Resource and User Management
  • 05 Insecure Use of Cryptography
  • 06 Insecure Network Access Management
  • 07 Insecure Authentication Methods and Default Credentials
  • 08 Information Leakage

10. 09 Insecure Access to Resources and Management Components

11. 10 Insufficient Asset Management and Documentation

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the Infrastructure Top 10 normative documents.
  • 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references.
  • 01 through 10 — one document per vulnerability aligned with OWASP Infrastructure Security numbering.

How to use it

Copy the folder

Take microsoft/owasp-infrastructure from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.