Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
microsoft avatar

Owasp Llm

  • 39 installs
  • 1.3k repo stars
  • Updated July 27, 2026
  • microsoft/hve-core

owasp-llm is an agent skill encoding OWASP Top 10 for LLM Applications 2025 as queryable security reference documents.

About

The owasp-llm skill encodes the OWASP Top 10 for LLM Applications 2025 as machine-readable reference documents an agent can query when assessing LLM security risks. The SKILL.md entrypoint links eleven normative references covering prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. Each vulnerability document in references aligns with OWASP LLM Applications numbering and includes detection and remediation guidance restructured for agent consumption. A vulnerability index cross-references identifiers and categories across the set. Content derives from OWASP Foundation material under CC BY-SA 4.0 with agent-oriented restructuring noted in attribution. The skill is not user-invocable directly but supports security reviews, threat modeling, and remediation planning for LLM-powered products. Triggers include assessing LLM risks, OWASP LLM Top 10 review, or remediating prompt injection and excessive agency issues. Use whenever builders need authoritative OWASP LLM vulnerability references during design rev.

  • Eleven structured references for OWASP LLM Top 10 2025 vulnerabilities.
  • Vulnerability index with identifiers and cross-references.
  • Agent-consumable detection and remediation guidance per risk.
  • CC BY-SA 4.0 OWASP Foundation attribution and sourcing.
  • Covers prompt injection, supply chain, agency, and consumption risks.

Owasp Llm by the numbers

  • 39 all-time installs (skills.sh)
  • +3 installs in the week ending Jun 21, 2026 (Skillselion tracking)
  • Ranked #1,420 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

owasp-llm capabilities & compatibility

Capabilities
owasp llm top 10 vulnerability index · per risk detection guidance documents · per risk remediation reference material · cross referenced llm threat taxonomy · cc by sa licensed authoritative sourcing
Use cases
security audit · research
From the docs

What owasp-llm says it does

OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks.
SKILL.md
npx skills add https://github.com/microsoft/hve-core --skill owasp-llm

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs39
repo stars1.3k
Security audit3 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorymicrosoft/hve-core

What OWASP LLM security risks apply to my agent or LLM application and how do I remediate them?

Query structured OWASP Top 10 for LLM Applications 2025 references to identify, assess, and remediate security risks in large language model systems.

Who is it for?

Security reviewers and LLM builders assessing prompt injection, disclosure, agency, and supply chain risks.

Skip if: Skip for non-LLM application security, generic OWASP web app reviews, or automated penetration testing.

When should I use this skill?

User assesses LLM security risks, references OWASP LLM Top 10, or plans remediation for agent threats.

What you get

Structured vulnerability references with detection and remediation guidance aligned to OWASP LLM Top 10 2025.

Files

SKILL.mdMarkdownGitHub ↗

OWASP® LLM Top 10 — Skill Entry

This SKILL.md is the entrypoint for the OWASP LLM Top 10 skill.

The skill encodes the OWASP Top 10 for LLM Applications (2025) as structured, machine-readable references that an agent can query to identify, assess, and remediate security risks in large language model systems.

Normative references (LLM Top 10)

1. 00 Vulnerability Index 2. 01 Prompt Injection 3. 02 Sensitive Information Disclosure 4. 03 Supply Chain 5. 04 Data and Model Poisoning 6. 05 Improper Output Handling 7. 06 Excessive Agency 8. 07 System Prompt Leakage 9. 08 Vector and Embedding Weaknesses 10. 09 Misinformation 11. 10 Unbounded Consumption

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the LLM Top 10 normative documents.
  • 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references.
  • 01 through 10 — one document per vulnerability aligned with OWASP LLM Applications numbering.

Third-Party Attribution

Copyright © OWASP Foundation. OWASP® Top 10 for LLM Applications (2025) content is derived from works by the OWASP Foundation, licensed under CC BY-SA 4.0 (<https://creativecommons.org/licenses/by-sa/4.0/>). Source: <https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/> Modifications: Vulnerability descriptions restructured into agent-consumable reference documents with added detection and remediation guidance. OWASP® is a registered trademark of the OWASP Foundation. Use does not imply endorsement.

Related skills

FAQ

What does owasp-llm produce?

Queryable OWASP LLM Top 10 2025 reference documents with detection and remediation guidance per vulnerability.

When should I use owasp-llm?

When identifying or remediating LLM-specific security risks during design review or hardening.

Is owasp-llm safe to install?

Review the Security Audits panel on this page before installing in production.

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.