OWASP CI/CD Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in continuous integration and continuous delivery environments.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill cicd-vulnerabilities --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cicd Vulnerabilities?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-cicd-vulnerabilities)More formats (shields.io, HTML) on the badges page.
---
name: cicd-vulnerabilities
description: OWASP CI/CD Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in continuous integration and continuous delivery environments.
license: MIT
metadata:
authors: "OWASP CI/CD Security Project"
spec_version: "1.0"
framework_revision: "1.0.0"
last_updated: "2026-02-16"
skill_based_on: "https://github.com/chris-buckley/agnostic-prompt-standard"
content_based_on: "https://owasp.org/www-project-top-10-ci-cd-security-risks/"
---
# CI/CD Vulnerabilities — Skill Entry
This `SKILL.md` is the **entrypoint** for the CI/CD Vulnerabilities skill.
The skill encodes the **OWASP Top 10 CI/CD Security Risks** as structured, machine-readable references
that an agent can query to identify, assess, and remediate CI/CD pipeline security risks.
## Normative references (CI/CD Top 10)
1. [00 Vulnerability Index](references/00-vulnerability-index.md)
2. [01 Insufficient Flow Control Mechanisms](references/01-insufficient-flow-control-mechanisms.md)
3. [02 Inadequate Identity and Access Management](references/02-inadequate-identity-access-management.md)
4. [03 Dependency Chain Abuse](references/03-dependency-chain-abuse.md)
5. [04 Poisoned Pipeline Execution](references/04-poisoned-pipeline-execution.md)
6. [05 Insufficient PBAC](references/05-insufficient-pbac.md)
7. [06 Insufficient Credential Hygiene](references/06-insufficient-credential-hygiene.md)
8. [07 Insecure System Configuration](references/07-insecure-system-configuration.md)
9. [08 Ungoverned Usage of 3rd Party Services](references/08-ungoverned-usage-of-3rd-party-services.md)
10. [09 Improper Artifact Integrity Validation](references/09-improper-artifact-integrity-validation.md)
11. [10 Insufficient Logging and Visibility](references/10-insufficient-logging-visibility.md)
## Skill layout
- `SKILL.md` — this file (skill entrypoint).
- `references/` — the CI/CD Top 10 normative documents.
- `00-vulnerability-index.md` — master index of all vulnerability identifiers, categories, and cross-references.
- `01` through `10` — one document per vulnerability aligned with OWASP CI/CD Security numbering.
- `assets/` — reusable format and constants blocks.
- `constants/` — vulnerability catalog and category definitions.
- `constants-cicd-catalog-v1.0.0.md`
- `formats/` — output contract examples.
- `format-vulnerability-assessment-v1.0.0.md`
- `format-remediation-checklist-v1.0.0.md`
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!