Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
nickcrew avatar

Owasp Top 10

  • 668 installs
  • 28 repo stars
  • Updated June 29, 2026
  • nickcrew/claude-ctx-plugin

owasp-top-10 is a security assessment skill that runs structured OWASP Top 10 reviews across frontend, backend, APIs, databases, and integrations before release.

About

owasp-top-10 is a structured security workflow for developers and security reviewers preparing to ship production software. The skill walks through scoping and pre-assessment: inventorying in-scope components, documenting the technology stack, classifying sensitive data flows, mapping trust boundaries, and cataloging third-party integrations. It then applies OWASP Top 10 methodology from discovery through remediation tracking across frontend, backend, APIs, microservices, and databases. Developers invoke owasp-top-10 when they need a repeatable pre-release security pass rather than ad-hoc checklist scanning. The workflow emphasizes boundary definition, data-flow analysis, and tracked remediation instead of one-off vulnerability mentions without ownership or follow-up.

  • Structured 7-phase OWASP assessment workflow from scoping to remediation tracking
  • Application inventory, technology stack mapping, and data classification templates
  • Rules of engagement document with clear boundaries and emergency contacts
  • Feature-to-OWASP risk mapping table with priority levels
  • Remediation tracking and verification process

Owasp Top 10 by the numbers

  • 668 all-time installs (skills.sh)
  • +9 installs in the week ending Jul 26, 2026 (Skillselion tracking)
  • Ranked #452 of 2,202 Security skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Aug 4, 2026 (Skillselion catalog sync)
npx skills add https://github.com/nickcrew/claude-ctx-plugin --skill owasp-top-10

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs668
repo stars28
Security audit3 / 3 scanners passed
Last updatedJune 29, 2026
Repositorynickcrew/claude-ctx-plugin

How do you run an OWASP Top 10 security assessment?

Run structured OWASP Top 10 security assessments across their full application stack before shipping.

Who is it for?

Developers and security reviewers conducting a pre-ship OWASP Top 10 pass across a full-stack application.

Skip if: Penetration testers who only need exploit tooling without a structured OWASP scoping and remediation workflow.

When should I use this skill?

The user requests OWASP Top 10 review, pre-release security assessment, or remediation-tracked vulnerability scoping.

What you get

Scoped assessment inventory, trust-boundary map, OWASP Top 10 findings list, and remediation tracking artifacts.

  • assessment scope document
  • findings and remediation tracker

By the numbers

  • Covers the OWASP Top 10 vulnerability categories in a phased assessment workflow

Files

SKILL.mdMarkdownGitHub ↗

OWASP Top 10 Security Vulnerabilities

Expert guidance for identifying, preventing, and remediating the most critical web application security risks based on OWASP Top 10 2021.

When to Use This Skill

  • Conducting security audits and code reviews
  • Implementing secure coding practices in new features
  • Reviewing authentication and authorization systems
  • Assessing input validation and sanitization
  • Evaluating third-party dependencies for vulnerabilities
  • Designing security controls and defense-in-depth strategies
  • Preparing for security certifications or compliance audits
  • Investigating security incidents or suspicious behavior

OWASP Top 10 2021 Overview

Ranked by Risk Severity:

1. A01 - Broken Access Control (↑ from #5) 2. A02 - Cryptographic Failures (formerly Sensitive Data Exposure) 3. A03 - Injection (↓ from #1) 4. A04 - Insecure Design (NEW) 5. A05 - Security Misconfiguration 6. A06 - Vulnerable and Outdated Components 7. A07 - Identification and Authentication Failures 8. A08 - Software and Data Integrity Failures (NEW) 9. A09 - Security Logging and Monitoring Failures 10. A10 - Server-Side Request Forgery (SSRF) (NEW)

Quick Reference

Load detailed guidance for each vulnerability:

VulnerabilityReference File
Broken Access Controlskills/owasp-top-10/references/broken-access-control.md
Cryptographic Failuresskills/owasp-top-10/references/cryptographic-failures.md
Injectionskills/owasp-top-10/references/injection.md
Insecure Designskills/owasp-top-10/references/insecure-design.md
Security Misconfigurationskills/owasp-top-10/references/security-misconfiguration.md
Vulnerable Componentsskills/owasp-top-10/references/vulnerable-components.md
Authentication Failuresskills/owasp-top-10/references/authentication-failures.md
Integrity Failuresskills/owasp-top-10/references/integrity-failures.md
Logging & Monitoringskills/owasp-top-10/references/logging-monitoring.md
SSRFskills/owasp-top-10/references/ssrf.md
Prevention Strategiesskills/owasp-top-10/references/prevention-strategies.md
Assessment Workflowskills/owasp-top-10/references/assessment-workflow.md

Security Audit Workflow

1. Identify Scope: Determine application components and attack surface 2. Select Vulnerabilities: Choose relevant OWASP categories based on features 3. Load Reference: Read appropriate reference file(s) for detailed patterns 4. Analyze Code: Review code against vulnerable and secure patterns 5. Document Findings: Record vulnerabilities with severity and remediation 6. Verify Fixes: Test that remediations properly address issues 7. Test Security: Run automated security testing (SAST, DAST, SCA)

Core Security Principles

Defense in Depth

  • Layer security controls at network, application, data, and monitoring levels
  • Ensure failure of one control doesn't compromise entire system

Secure by Default

  • Deny all access by default, explicitly grant permissions
  • Fail securely (errors don't expose sensitive information)
  • Minimize attack surface (disable unused features)
  • Apply least privilege to all accounts and services

Input Validation

  • Validate type, length, format, and allowed values
  • Use allow-lists over deny-lists
  • Sanitize for specific context (SQL, HTML, shell, etc.)
  • Never trust client input

Common Mistakes

1. Trusting User Input: Always validate and sanitize all user-supplied data 2. Rolling Your Own Crypto: Use established libraries (bcrypt, AES-256) 3. Exposing Errors: Log detailed errors internally, show generic messages to users 4. Missing Authorization: Check permissions on every request, not just UI 5. Weak Session Management: Use secure, httpOnly, sameSite cookies with HTTPS 6. Ignoring Dependencies: Regularly audit and update third-party libraries 7. No Logging: Log security events for detection and incident response 8. Default Configurations: Harden all systems, disable defaults

Security Testing Tools

SAST (Static): SonarQube, Semgrep, ESLint security plugins DAST (Dynamic): OWASP ZAP, Burp Suite SCA (Dependencies): npm audit, Snyk, Dependabot Secrets Scanning: GitGuardian, TruffleHog Penetration Testing: Metasploit, Kali Linux tools

Resources

  • OWASP Top 10 2021: https://owasp.org/Top10/
  • OWASP Cheat Sheets: https://cheatsheetseries.owasp.org/
  • OWASP ASVS: Application Security Verification Standard
  • CWE Top 25: Common Weakness Enumeration
  • NIST Cybersecurity Framework: https://www.nist.gov/cyberframework
  • CVE Database: https://cve.mitre.org/
  • Snyk Vulnerability DB: https://snyk.io/vuln/

Related skills

How it compares

Choose owasp-top-10 for methodology and remediation tracking across a full stack; use narrower SAST or secrets skills for single-layer automated scans.

FAQ

What does owasp-top-10 assess?

owasp-top-10 runs structured OWASP Top 10 security assessments across frontend, backend, APIs, microservices, databases, and third-party integrations. The workflow starts with scoping, stack inventory, and trust-boundary mapping.

When should I use owasp-top-10?

Use owasp-top-10 before shipping when you need a repeatable security assessment with remediation tracking. The skill covers data classification, integration cataloging, and OWASP-aligned findings rather than ad-hoc scans.

Is Owasp Top 10 safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.