Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
microsoft avatar

Owasp Cicd

  • 35 installs
  • 1.3k repo stars
  • Updated July 27, 2026
  • microsoft/hve-core

owasp-cicd is an agent skill knowledge base for OWASP CI/CD Top 10 pipeline security risks and remediations.

About

The owasp-cicd skill encodes the OWASP Top 10 CI/CD Security Risks as structured, machine-readable references an agent can query during pipeline security reviews. The SKILL.md entrypoint points to eleven normative documents: a vulnerability index plus ten risk files covering insufficient flow control, inadequate IAM, dependency chain abuse, poisoned pipeline execution, insufficient PBAC, credential hygiene, insecure system configuration, ungoverned third-party services, improper artifact integrity validation, and insufficient logging. Each reference document includes detection and remediation guidance derived from OWASP Foundation content under CC BY-SA 4.0. The skill layout separates the entrypoint from references/ numbered 00 through 10 aligned with OWASP CI/CD numbering. Agents load specific vulnerability files when assessing pipeline configurations, workflow permissions, secret handling, or artifact signing gaps. It is a knowledge-base skill rather than an execution workflow. Use when reviewing CI/CD pipelines for OWASP CI/CD Top 10 compliance or investigating specific pipeline security weaknesses.

  • Entrypoint for OWASP Top 10 CI/CD Security Risks reference corpus.
  • Eleven normative documents from vulnerability index through risk 10.
  • Structured detection and remediation guidance per CI/CD risk category.
  • CC BY-SA 4.0 OWASP Foundation content with agent-consumable formatting.
  • Covers flow control, IAM, dependencies, PPE, credentials, and logging risks.

Owasp Cicd by the numbers

  • 35 all-time installs (skills.sh)
  • +6 installs in the week ending Jun 21, 2026 (Skillselion tracking)
  • Ranked #1,456 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

owasp-cicd capabilities & compatibility

Capabilities
ci/cd top 10 vulnerability index lookup · per risk detection guidance references · per risk remediation guidance references · flow control and iam risk assessment · artifact integrity and logging risk coverage
Use cases
security audit · ci cd
From the docs

What owasp-cicd says it does

identify, assess, and remediate CI/CD pipeline security risks.
SKILL.md
npx skills add https://github.com/microsoft/hve-core --skill owasp-cicd

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs35
repo stars1.3k
Security audit3 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorymicrosoft/hve-core

What CI/CD security risks apply to my pipeline and how do I remediate them?

Query OWASP CI/CD Top 10 references to identify, assess, and remediate pipeline security risks.

Who is it for?

Security reviewers assessing CI/CD pipelines against OWASP CI/CD Top 10 categories.

Skip if: Skip for MCP-specific risks or general application OWASP Top 10 web vulnerabilities.

When should I use this skill?

User asks about CI/CD pipeline security risks, OWASP CI/CD Top 10, or pipeline hardening.

What you get

Targeted OWASP CI/CD risk assessment with detection steps and remediation guidance from reference docs.

Files

SKILL.mdMarkdownGitHub ↗

OWASP® CI/CD Top 10 — Skill Entry

This SKILL.md is the entrypoint for the OWASP CI/CD Top 10 skill.

The skill encodes the OWASP Top 10 CI/CD Security Risks as structured, machine-readable references that an agent can query to identify, assess, and remediate CI/CD pipeline security risks.

Normative references (CI/CD Top 10)

1. 00 Vulnerability Index 2. 01 Insufficient Flow Control Mechanisms 3. 02 Inadequate Identity and Access Management 4. 03 Dependency Chain Abuse 5. 04 Poisoned Pipeline Execution 6. 05 Insufficient PBAC 7. 06 Insufficient Credential Hygiene 8. 07 Insecure System Configuration 9. 08 Ungoverned Usage of 3rd Party Services 10. 09 Improper Artifact Integrity Validation 11. 10 Insufficient Logging and Visibility

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the CI/CD Top 10 normative documents.
  • 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references.
  • 01 through 10 — one document per vulnerability aligned with OWASP CI/CD Security numbering.

Third-Party Attribution

Copyright © OWASP Foundation. OWASP® Top 10 CI/CD Security Risks content is derived from works by the OWASP Foundation, licensed under CC BY-SA 4.0 (<https://creativecommons.org/licenses/by-sa/4.0/>). Source: <https://owasp.org/www-project-top-10-ci-cd-security-risks/> Modifications: Vulnerability descriptions restructured into agent-consumable reference documents with added detection and remediation guidance. OWASP® is a registered trademark of the OWASP Foundation. Use does not imply endorsement.

Related skills

FAQ

What does owasp-cicd cover?

Ten OWASP CI/CD security risks plus a vulnerability index with detection and remediation references.

How should an agent use owasp-cicd?

Load specific numbered reference documents from references/ for the relevant CI/CD risk category.

Is owasp-cicd safe to install?

Review the Security Audits panel on this page before installing in production.

Securityauditcompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.