Assess an LLM-backed application against the OWASP Top 10 for LLM Applications, producing a per-category finding set with severity and mitigations. Use when reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.
Pro scans all 2 files and shows the line behind each finding
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill owasp-llm-top10 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Owasp Llm Top10?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-owasp-llm-top10)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: owasp-llm-top10
description: >-
Assess an LLM-backed application against the OWASP Top 10 for LLM Applications,
producing a per-category finding set with severity and mitigations. Use when
reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.
---
# Goal
A structured assessment across all ten OWASP LLM risk categories, with concrete
findings (or "not applicable / mitigated") and prioritized mitigations.
# Steps
1. **Map the system.** Identify the model(s), prompts/system prompts, data
sources (RAG/tools), user input paths, output sinks, and what privileges the
LLM and its tools hold. A quick `ai-threat-model` pass helps here.
2. **Walk each category** (see `reference.md` for the full LLM Top 10 with checks
and mitigations): prompt injection, sensitive information disclosure, supply
chain, data/model poisoning, improper output handling, excessive agency,
system-prompt leakage, vector/embedding weaknesses, misinformation, and
unbounded consumption.
3. **For each**: state applicability, evidence/observation, severity, and the
specific mitigation. Use `prompt-injection-test` to substantiate injection
findings rather than asserting them.
4. **Rank** the findings (`threat-modeling:risk-rank`) and summarize top risks.
# Output
A per-category table (category · applicable? · finding · severity · mitigation)
plus a ranked top-risks list. For any finding backed by actual code (prompt
construction, output handling, tool-call authorization, etc.), include a
before/after snippet pair rather than just describing the fix:
```
**Vulnerable** (`file:line`):
```<lang>
<exact vulnerable snippet>
```
**Fixed:**
```<lang>
<minimal corrected snippet — same shape, only the fix changed>
```
```
Keep both snippets minimal (just the vulnerable statement + immediate context).
Route findings through `security-reporting:finding` for formal writeups.
# Notes
Read `reference.md` for the authoritative category list, signs to look for, and
mitigations. Keep testing authorized and within the app's intended scope. Excessive
agency and improper output handling are the categories most often missed — give
them explicit attention.
The Top 10 increasingly folds in agentic risk (LLM06 Excessive Agency and
related entries) as apps move from single-turn chat to tool-using agents. For
MCP-specific and multi-tool agent trust-boundary review, see
`agentic-ai-security:mcp-security-review`; for the full agent threat model see
`agentic-ai-security:agent-security-review`.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!