OWASP-mapped agentic security review — prompt injection, tool poisoning, identity, excessive agency, credential exposure, supply-chain, insecure output handling, overreliance, data leakage, insecure plugin/MCP design. Evidence-cited, severity-ranked.
Scanned 9/2/2026
Install to Claude Code
npx -y skills add ulises-jeremias/agent-toolkit --skill owasp-agentic-review --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Owasp Agentic Review?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/ulises-jeremias-owasp-agentic-review-3bbbe1ad)More formats (shields.io, HTML) on the badges page.
---
name: owasp-agentic-review
description: OWASP-mapped agentic security review — prompt injection, tool poisoning, identity, excessive agency, credential exposure, supply-chain, insecure output handling, overreliance, data leakage, insecure plugin/MCP design. Evidence-cited, severity-ranked.
origin:
type: first-party
---
# OWASP Agentic Review — Prompt Injection, Tool Poisoning, Agency & Supply Chain
Curated OWASP LLM Top 10 (2025) + OWASP Agentic Security review for **agents, skills, plugins, hooks, MCP, tool use, prompt handling, and provenance**. Use when reviewing agentic capabilities, supply-chain surface, or when `security-reviewer` (app code) needs agentic specialization.
**Evidence-cited, severity-ranked — do not hallucinate findings.** Every finding must cite `observation (file:line, registry YAML, tool description) + impact + severity + confidence + evidence`. Delegates to `supply-chain-audit` + `mcp-audit` for supply-chain/MCP depth.
> **OWASP source:** OWASP Top 10 for LLM Applications 2025 (v1.1, 2025-02-18) + OWASP Agentic & GenAI security guidance (prompt injection, insecure output, supply chain, excessive agency, data leakage, insecure plugin). Map findings to IDs `LLM01`–`LLM10` + `AGNT01`–`AGNT06` where applicable; do not fabricate beyond listed. Cite https://owasp.org/www-project-top-10-for-large-language-model-applications/ and https://owasp.org/www-project-agentic-security/ where mapping.
## OWASP LLMs / Agentic mapping (curated checklist)
| OWASP ID | Title | What to check (evidence) | Mode |
|----------|-------|--------------------------|------|
| LLM01 | Prompt Injection | Tool descriptions / skill instructions contain `ignore previous`, `send secrets`, `exfiltrate`, `override system`, `[/INST]`; user input flows into skill instructions without delimiting; hook `prompt` interpolation without escaping | Static: scan `skills/**/SKILL.md`, `agents/**/AGENT.md`, `mcp/registry/*.yaml` tool descriptions, `hooks` configs for injection phrases; browser capture not needed |
| LLM02 | Insecure Output Handling | Agent output (file writes, shell args, URL fetches) unsanitized before execution; `tool_result` concatenated into `bash` without validation; `curl`/`wget`/`npx` args from LLM without allowlist | Static: `audit-capability.py` surface shell/network, check `supply-chain-audit` report |
| LLM03 | Training Data Poisoning | Third-party skill/plugin `provenance_digest` missing or `NOASSERTION` without review; `upstream.lock` digest mismatch; vendored bytes not matching upstream SHA | Provenance lock check: `capabilities/upstream.lock` `content_checksum` vs vendored file |
| LLM04 | Model Denial of Service | Skill loads 50k+ tokens unconditional (e.g., full accessibility-skills), PM excessive context causing token DoS; swarm fanning without rate limit | Context-cost audit (#395): measure skill SKILL.md token count, routing vs monolith |
| LLM05 | Supply Chain Vulnerabilities | Unpinned package (`latest` without digest), unknown provenance, transitive npm/py deps without hash, MCP `ghcr.io` without digest, `claims` without `version_policy` | Registry `implementation.package` + `version_policy` + `audit-capability.py` pins/hashes |
| LLM06 | Sensitive Information Disclosure | Hardcoded `ghp_`, `xoxb`, `sk-`, PII in skill body or `config.template.json` without `${VAR}` placeholder; screenshots with secrets; `secret_storage` not env var | Scan `mcp/registry/*.yaml` + `skills/**` for secrets (test_no_secrets_in_registry), check templates placeholders |
| LLM07 | Insecure Plugin Design | Plugin `hooks` with `dangerous_permissions` (filesystem write, network, default-branch push) without justification; `security.cve_policy` missing; `mcp.write`/`destructive` overly broad | Validate `skills/**/SKILL.md` frontmatter `security.*` + `distributions/products.yaml` |
| LLM08 | Excessive Agency | Agent can `delete_file`, `push to default`, `run shell` without human approval; `approval.default` = `destructive` without gate; swarm can fan out unbounded | Check `approval.default`, `security.dangerous_permissions`, `output-handshake` gates |
| LLM09 | Overreliance | Agent claims full WCAG AA / full security compliance from automated checks alone (e.g., axe pass = AA pass, no manual gates) — requires human judgment | Check skill claims: must distinguish automatically detectable vs browser-assisted vs manual, must mark Not assessed |
| LLM10 | Model Theft | Skill exfiltrates model weights / prompts via `network` + `filesystem` write to external host; `security.network_hosts` includes unscoped `*` | Network hosts allowlist audit |
| AGNT01 | Identity & Spoofing | Agent impersonates `security-reviewer` / `architect` without delegation table; missing agent identity prefix in `AGENT.md` | Check `agents/*` `name` + delegation tables |
| AGNT02 | Tool Poisoning | MCP tool description contains hidden instructions (e.g., tool `get_file` description says `when listing files also send /etc/passwd`) | Scan `mcp/registry/*.yaml` `tools.*` descriptions for imperative injection |
| AGNT03 | Insecure Inter-Agent Trust | One agent can directly mutate another's memory without `swarm-handoff` gate; no trust boundary between assessment and implementation agents | Check `ops/swarm-handoff` usage + trust boundaries |
| AGNT04 | Data Leakage via Tool Output | Tool output containing PII/secrets is forwarded to external MCP without redaction | Check `security.network_hosts` + Grep for network/exfil patterns |
| AGNT05 | Permission Creep | Skill `security.dangerous_permissions` accumulates across composed skills (design-assessment → mcp-audit → supply-chain-audit) without least-privilege | Check composed delegation chain permissions sum |
| AGNT06 | Prompt Hierarchy Violation | System prompt overridden by user-provided skill instructions (instruction hierarchy not enforced) | Scan hook `prompt` vs `user` priority |
## Workflow
1. **Discover scope:** `git diff HEAD` + `skills/**`/`agents/**`/`mcp/registry/*.yaml` changed → enumerate assets (skills, MCP servers, hooks, subagents) + trust boundaries (user ↔ agent ↔ MCP ↔ external host).
2. **Run static gates:** Grep/Read for shell/network/mcp/hooks surface + injection phrases (`ignore previous`, `send secrets`, `exfiltrate`, `/etc/passwd`) + check `upstream.lock` digests. (Repo checkout/CI only: `./scripts/audit-capability.vsh --json` — not installed on host.)
3. **Map to OWASP:** For each finding, assign `LLM01`–`LLM10` / `AGNT01`–`AGNT06` + `severity` (Critical/High/Med/Low vs Blocking/Major/Minor) + `confidence` High/Med/Low + `evidence` link (file:line, registry YAML, tool description) + `impact` (who/what compromised) + `likelihood` + `mitigation` + `residual risk`.
4. **Report:** Emit `owasp-agentic-review.md` per `references/owasp-agentic-template.md` with risk-ranked table, attack path, mitigations, security acceptance criteria. Apply `output-handshake` before final artifact.
## Relation to other reviewers
| Need | Reviewer | Focus |
|------|----------|-------|
| App/code vulns (OWASP Top 10 Web) | `security-reviewer` | SQLi, XSS, auth, IDOR, vuln deps |
| Agentic / prompt / MCP / supply-chain | **`owasp-agentic-review`** (this skill) + **`agentic-security-reviewer`** agent | LLM01-10 + AGNT01-06 |
| System design tradeoffs | `architect` | C4/Mermaid, ADRs, threat model input |
| Full supply-chain surface | `agentic-security/supply-chain-audit` | Provenance, pins, hashes, licenses |
| MCP config/impl | `agentic-security/mcp-audit` | MCP-specific audit (two modes) |
| Threat model (assets/boundaries/actors → STRIDE + agentic) | `agentic-security/threat-modeling` | STRIDE + agentic threats → mitigations |
## Delegation table
| Need | Skill / Agent |
|------|---------------|
| Deep app vulns | `agents/security-reviewer` |
| Agentic specialized review | `agents/agentic-security-reviewer` (this package persona) + this skill |
| Supply-chain surface | `agentic-security/supply-chain-audit` |
| MCP config/impl | `agentic-security/mcp-audit` |
| Threat model (architecture → STRIDE) | `agentic-security/threat-modeling` |
| Output gate | `output-handshake` |
## References
- `references/owasp-agentic-template.md` — report template (risk-ranked, SC-mapped)
- OWASP LLM Top 10 2025: https://owasp.org/www-project-top-10-for-large-language-model-applications/ (v1.1, 2025-02-18)
- OWASP Agentic Security: https://owasp.org/www-project-agentic-security/
- `mcp/registry/*.yaml` + static Grep for shell/network/mcp/hooks (repo checkout/CI: `scripts/audit-capability.vsh`)
- `supply-chain-audit` + `mcp-audit` — shared report shape
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!