OWASP Agentic Skills Top 10

The OWASP Agentic Skills Top 10 documents the most critical security risks in AI agent skills across platforms like OpenClaw, Claude Code, Cursor, and VS Code. It addresses the security of the behavioral layer where skills define how agents orchestrate multi-step workflows, filling a gap between model-level risks and protocol-level risks. The project is based on extensive real-world evidence from 2026 incidents, including the ClawHavoc campaign with over 1,180 malicious skills, widespread credential exposure, and critical vulnerabilities in major platforms. The top risks include malicious skills, supply chain compromise, over-privileged skills, insecure metadata, unsafe deserialization, weak isolation, update drift, poor scanning, lack of governance, and cross-platform reuse. The project provides detailed risk descriptions, attack scenarios, preventive mitigations, mappings to existing OWASP projects, a proposed universal skill format, and practical guidance for security teams, skill developers, and platform vendors. 

https://github.com/kenhuangus/agentic-skills-top-10

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities