EXPERIMENTAL. Use when code needs a security review against the OWASP Top 10:2025 — access control, misconfiguration, supply chain, cryptography, injection, insecure design, authentication, integrity, logging and alerting, and mishandled exceptional conditions. Not for penetration testing a running system, not for infrastructure-only scanning, and not for fixing what it finds.
npx skills add https://github.com/Ovid/paad --skill agentic-owasp
This is a project-specific skill. The detailed checklist and procedures are in:
.kiro/skills/agentic-owasp/SKILL.md
Please refer to that file for the full criteria.
Take ovid/agentic-owasp from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.