Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
microsoft avatar

Owasp Agentic

  • 42 installs
  • 1.3k repo stars
  • Updated July 27, 2026
  • microsoft/hve-core

owasp-agentic is an agent skill knowledge base for OWASP Top 10 Agentic Applications 2026 security risk assessment and remediation.

About

The owasp-agentic skill encodes the OWASP Top 10 for Agentic Applications 2026 as structured machine-readable references an agent can query to identify, assess, and remediate security risks in AI agent systems. The entrypoint links eleven normative reference documents from vulnerability index through agent goal hijack, tool misuse, identity abuse, supply chain vulnerabilities, unexpected code execution, memory poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue agents. Each reference document includes detection and remediation guidance restructured from OWASP Foundation CC BY-SA 4.0 content. The skill is not user-invocable directly but serves as a knowledge base for security review workflows. Layout separates SKILL.md entrypoint from references directory with per-vulnerability documents aligned to OWASP Agentic Security numbering. Use when assessing agent architecture security, mapping threats to OWASP categories, or drafting remediation plans for agentic application risk.

  • Encodes OWASP Agentic Top 10 2026 as eleven structured reference documents.
  • Covers goal hijack, tool misuse, supply chain, memory poisoning, and rogue agents.
  • Each vulnerability doc includes detection and remediation guidance.
  • Vulnerability index provides cross-references and identifier lookup.
  • Licensed CC BY-SA 4.0 content from OWASP Foundation with attribution.

Owasp Agentic by the numbers

  • 42 all-time installs (skills.sh)
  • +5 installs in the week ending Jun 21, 2026 (Skillselion tracking)
  • Ranked #1,387 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

owasp-agentic capabilities & compatibility

Capabilities
owasp agentic top 10 reference index · per vulnerability detection guidance · remediation recommendations per category · cross reference vulnerability identifiers · structured machine readable security knowledge b
Use cases
security audit
From the docs

What owasp-agentic says it does

OWASP Agentic Security Top 10 knowledge base for identifying, assessing, and remediating AI agent system security risks.
SKILL.md
machine-readable references that an agent can query to identify, assess, and remediate security risks
SKILL.md
OWASP Top 10 for Agentic Applications (2026)
SKILL.md
npx skills add https://github.com/microsoft/hve-core --skill owasp-agentic

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs42
repo stars1.3k
Security audit3 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorymicrosoft/hve-core

What OWASP agentic security risks apply to my AI agent system and how do I remediate them?

Identify, assess, and remediate AI agent security risks using OWASP Agentic Top 10 references.

Who is it for?

Security reviewers assessing AI agent architectures against OWASP Agentic Top 10 categories.

Skip if: Skip for non-agent applications or general web app OWASP Top 10 without agentic components.

When should I use this skill?

User assesses agent security, asks about OWASP agentic risks, or reviews agent tool and memory threats.

What you get

Mapped threats to OWASP categories with detection guidance and remediation steps from normative references.

Files

SKILL.mdMarkdownGitHub ↗

OWASP® Agentic Top 10 — Skill Entry

This SKILL.md is the entrypoint for the OWASP Agentic Top 10 skill.

The skill encodes the OWASP Top 10 for Agentic Applications (2026) as structured, machine-readable references that an agent can query to identify, assess, and remediate security risks in AI agent systems.

Normative references (Agentic Top 10)

1. 00 Vulnerability Index 2. 01 Agent Goal Hijack 3. 02 Tool Misuse and Exploitation 4. 03 Identity and Privilege Abuse 5. 04 Agentic Supply Chain Vulnerabilities 6. 05 Unexpected Code Execution 7. 06 Memory and Context Poisoning 8. 07 Insecure Inter-Agent Communication 9. 08 Cascading Failures 10. 09 Human-Agent Trust Exploitation 11. 10 Rogue Agents

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the Agentic Top 10 normative documents.
  • 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references.
  • 01 through 10 — one document per vulnerability aligned with OWASP Agentic Security numbering.

Third-Party Attribution

Copyright © OWASP Foundation. OWASP® Top 10 for Agentic Applications (2026) content is derived from works by the OWASP Foundation, licensed under CC BY-SA 4.0 (<https://creativecommons.org/licenses/by-sa/4.0/>). Source: <https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/> Modifications: Vulnerability descriptions restructured into agent-consumable reference documents with added detection and remediation guidance. OWASP® is a registered trademark of the OWASP Foundation. Use does not imply endorsement.

Related skills

FAQ

What does owasp-agentic cover?

Eleven OWASP Agentic Top 10 2026 vulnerability references with detection and remediation guidance for AI agent systems.

When should I use owasp-agentic?

When identifying, assessing, or remediating security risks in AI agent applications using OWASP categories.

Is owasp-agentic safe to install?

Review the Security Audits panel on this page before installing in production.

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.