Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Owasp Security Review

ASecurity

Review code and architectures against the OWASP Top 10:2025. Use to audit for vulnerabilities, guide remediation, or write secure code. Triggers: "security review", "OWASP audit", "check for vulnerabilities", "is this code secure".

4 stars
0 votes
0 copies
1 views
Added 9/19/2026
developmentrustgosqlrailsawssecurity

Security Analysis

A100/100

Pro scans all 12 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add jgamaraalv/delivery-loop --skill owasp-security-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Owasp Security Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Owasp Security Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jgamaraalv-owasp-security-review/badge)](https://www.skillsdirectory.com/skills/jgamaraalv-owasp-security-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: owasp-security-review
description: Review code and architectures against the OWASP Top 10:2025. Use to audit for vulnerabilities, guide remediation, or write secure code. Triggers: "security review", "OWASP audit", "check for vulnerabilities", "is this code secure".
---

# OWASP Top 10:2025 Security Review

<quick_reference>

## Quick reference

| #   | Category                              | Key risk                                                               | Avg incidence |
| --- | ------------------------------------- | ---------------------------------------------------------------------- | ------------- |
| A01 | Broken Access Control                 | Unauthorized data access, privilege escalation, SSRF, CSRF             | 3.74%         |
| A02 | Security Misconfiguration             | Default creds, verbose errors, missing hardening, XXE                  | 3.00%         |
| A03 | Software Supply Chain Failures        | Vulnerable/malicious dependencies, compromised build pipelines         | 5.72%         |
| A04 | Cryptographic Failures                | Weak algorithms, hardcoded keys, missing encryption, weak hashing      | 3.80%         |
| A05 | Injection                             | SQLi, XSS, command injection, LDAP/XPath/EL injection                  | 3.08%         |
| A06 | Insecure Design                       | Missing threat modeling, business logic flaws, insufficient controls   | 1.86%         |
| A07 | Authentication Failures               | Credential stuffing, weak passwords, session fixation, missing MFA     | 2.92%         |
| A08 | Software/Data Integrity Failures      | Unsigned updates, insecure deserialization, untrusted CDN code         | 2.75%         |
| A09 | Security Logging & Alerting Failures  | Missing audit logs, no alerting, log injection, sensitive data in logs | 3.91%         |
| A10 | Mishandling of Exceptional Conditions | Failing open, info leakage via errors, unchecked return values         | 2.95%         |

## Severity classification

Use these severity levels when reporting findings:

- **Critical**: Directly exploitable, leads to full system compromise or mass data breach (e.g., SQLi with no parameterization, hardcoded admin credentials, missing auth on admin endpoints).
- **High**: Exploitable with moderate effort, significant data exposure or privilege escalation (e.g., IDOR, weak password hashing, SSRF, deserialization of untrusted data).
- **Medium**: Exploitable under specific conditions, limited impact (e.g., missing CSRF protection, verbose error messages, missing security headers).
- **Low**: Defense-in-depth issue, minimal direct impact (e.g., missing rate limiting, incomplete logging, suboptimal crypto configuration).

</quick_reference>

<workflow>

## Workflows

<phase_1_code_review>
### Code review for security

Systematically check the code against each relevant category:

1. **Identify the code's surface area** — Does it handle auth? User input? File uploads? External data? Crypto? Error responses?
2. **Select relevant categories** from the table above based on the surface area.
3. **Load the reference file** for each relevant category and check the code against the "What to look for" section.
4. **Report findings** grouped by category with severity (Critical/High/Medium/Low), the specific code location, and a concrete fix.

Priority order for review (highest impact first):

- `[CRITICAL]` Input handling code → A05 (Injection), A01 (Access Control)
- `[CRITICAL]` Auth/session code → A07 (Authentication), A01 (Access Control)
- `[HIGH]` Data storage/transmission → A04 (Cryptographic Failures)
- `[HIGH]` Configuration/deployment → A02 (Security Misconfiguration)
- `[HIGH]` Dependencies → A03 (Supply Chain)
- `[MEDIUM]` Error handling → A10 (Exceptional Conditions), A09 (Logging)
- `[MEDIUM]` Architecture/design → A06 (Insecure Design)
- `[MEDIUM]` Data integrity → A08 (Integrity Failures)
</phase_1_code_review>

<phase_2_audit_checklist>
### Security audit checklist

Generate a checklist for a feature or codebase:

1. Read the feature/codebase to understand its scope.
2. For each of the 10 categories, determine if it applies.
3. For applicable categories, load the reference file and produce a checklist of items to verify.
4. Output a markdown checklist grouped by category.
</phase_2_audit_checklist>

<phase_3_remediation>
### Remediation guidance

When a vulnerability is identified:

1. Classify it into the correct OWASP category.
2. Load the corresponding reference file.
3. Apply the prevention checklist to produce a specific, actionable fix.
4. Provide a code example of the fix when possible.
</phase_3_remediation>

</workflow>

<references>

## Reference files

Load the relevant file when you need detailed guidance for a specific category:

- **A01 Broken Access Control** — authorization checks, IDOR, CORS, CSRF, path traversal: [references/a01-broken-access-control.md](references/a01-broken-access-control.md)
- **A02 Security Misconfiguration** — hardening, default creds, error messages, headers, XXE: [references/a02-security-misconfiguration.md](references/a02-security-misconfiguration.md)
- **A03 Supply Chain Failures** — dependency management, SBOM, build pipeline security: [references/a03-supply-chain-failures.md](references/a03-supply-chain-failures.md)
- **A04 Cryptographic Failures** — encryption, hashing, key management, TLS, PRNG: [references/a04-cryptographic-failures.md](references/a04-cryptographic-failures.md)
- **A05 Injection** — SQL, XSS, command, ORM, LDAP, template injection: [references/a05-injection.md](references/a05-injection.md)
- **A06 Insecure Design** — threat modeling, business logic, secure SDLC: [references/a06-insecure-design.md](references/a06-insecure-design.md)
- **A07 Authentication Failures** — credential stuffing, MFA, session management, password policy: [references/a07-authentication-failures.md](references/a07-authentication-failures.md)
- **A08 Integrity Failures** — deserialization, code signing, untrusted sources, CDN trust: [references/a08-integrity-failures.md](references/a08-integrity-failures.md)
- **A09 Logging & Alerting** — audit trails, log injection, alerting, sensitive data in logs: [references/a09-logging-alerting-failures.md](references/a09-logging-alerting-failures.md)
- **A10 Exceptional Conditions** — error handling, fail-closed, resource cleanup, info leakage: [references/a10-exceptional-conditions.md](references/a10-exceptional-conditions.md)

</references>

<output>
When reporting security findings, use the template in [template.md](template.md) for each finding.
</output>

Attribution

jgamaraalvjgamaraalv
View sourceSee grades on GitHubMore from jgamaraalv →
SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes
View all in development →