Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Owasp Llm Top10

ASecurity

Assess an LLM-backed application against the OWASP Top 10 for LLM Applications, producing a per-category finding set with severity and mitigations. Use when reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.

8 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsrustgotestingsecurity

Works with

mcp

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add jassics/awesome-claude-security --skill owasp-llm-top10 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Owasp Llm Top10?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Owasp Llm Top10
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jassics-owasp-llm-top10/badge)](https://www.skillsdirectory.com/skills/jassics-owasp-llm-top10)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: owasp-llm-top10
description: >-
  Assess an LLM-backed application against the OWASP Top 10 for LLM Applications,
  producing a per-category finding set with severity and mitigations. Use when
  reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.
---

# Goal

A structured assessment across all ten OWASP LLM risk categories, with concrete
findings (or "not applicable / mitigated") and prioritized mitigations.

# Steps

1. **Map the system.** Identify the model(s), prompts/system prompts, data
   sources (RAG/tools), user input paths, output sinks, and what privileges the
   LLM and its tools hold. A quick `ai-threat-model` pass helps here.
2. **Walk each category** (see `reference.md` for the full LLM Top 10 with checks
   and mitigations): prompt injection, sensitive information disclosure, supply
   chain, data/model poisoning, improper output handling, excessive agency,
   system-prompt leakage, vector/embedding weaknesses, misinformation, and
   unbounded consumption.
3. **For each**: state applicability, evidence/observation, severity, and the
   specific mitigation. Use `prompt-injection-test` to substantiate injection
   findings rather than asserting them.
4. **Rank** the findings (`threat-modeling:risk-rank`) and summarize top risks.

# Output

A per-category table (category · applicable? · finding · severity · mitigation)
plus a ranked top-risks list. For any finding backed by actual code (prompt
construction, output handling, tool-call authorization, etc.), include a
before/after snippet pair rather than just describing the fix:

```
**Vulnerable** (`file:line`):
```<lang>
<exact vulnerable snippet>
```
**Fixed:**
```<lang>
<minimal corrected snippet — same shape, only the fix changed>
```
```
Keep both snippets minimal (just the vulnerable statement + immediate context).
Route findings through `security-reporting:finding` for formal writeups.

# Notes

Read `reference.md` for the authoritative category list, signs to look for, and
mitigations. Keep testing authorized and within the app's intended scope. Excessive
agency and improper output handling are the categories most often missed — give
them explicit attention.

The Top 10 increasingly folds in agentic risk (LLM06 Excessive Agency and
related entries) as apps move from single-turn chat to tool-using agents. For
MCP-specific and multi-tool agent trust-boundary review, see
`agentic-ai-security:mcp-security-review`; for the full agent threat model see
`agentic-ai-security:agent-security-review`.

Attribution

jassicsjassics
View sourceSee grades on GitHubMore from jassics →
SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1085031 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

696681 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →