Owasp Security — Security skill for Claude Code
OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026) with code review checklists, secure patterns, and language-specific quirks for 20+ languages.
How to install Owasp Security
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open agamm/claude-code-owasp and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Owasp Security does
A Claude Code skill providing the latest OWASP security best practices (2025-2026) for developers building secure applications.
Alternatives in Security
- Security Best Practices — Review code for language-specific security vulnerabilities 14.6k ★
- Skill Audit — Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review 2.8k ★
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
README
OWASP Security Skill for Claude Code
A Claude Code skill providing the latest OWASP security best practices (2025-2026) for developers building secure applications.
Quick Install (One Line)
Add this skill to any project with a single command:
curl -sL https://raw.githubusercontent.com/agam/claude-code-owasp/main/.claude/skills/owasp-security/SKILL.md -o .claude/skills/owasp-security/SKILL.md --create-dirs
Or install globally for all projects:
curl -sL https://raw.githubusercontent.com/agam/claude-code-owasp/main/.claude/skills/owasp-security/SKILL.md -o ~/.claude/skills/owasp-security/SKILL.md --create-dirs
What's Included
Claude Code Skill
Location: `.claude/skills/owasp-security/SKILL.md`
- OWASP Top 10:2025 quick reference table
- Security code review checklists for input handling, auth, access control, data protection, and error handling
- Secure code patterns with unsafe/safe examples
- OWASP Agentic AI Security (2026) - ASI01-ASI10 risks for AI agent systems
- ASVS 5.0 key requirements by verification level
- Language-specific security quirks for 20+ languages with deep analysis guidance
Research Report
Location: `OWASP-2025-2026-Report.md`
Comprehensive documentation covering all OWASP 2025-2026 standards.
Usage
Once installed, Claude Code automatically activates this skill when you:
- Review code for security vulnerabilities
- Implement authentication or authorization
- Handle user input or external data
- Work with cryptography or password storage
- Design API endpoints
- Build AI agent systems
Example Prompts
"Review this code for security issues"
"Is this authentication implementation secure?"
"What are the security risks in this Python code?"
"Help me implement secure session management"
"Check this AI agent for OWASP agentic risks"
Covered Standards
| Standard | Version | Focus |
|---|
...
Related Skills
AuraKit
npx @smorky85/aurakit Fullstack development skill with 37 modes (BUILD/FIX/CLEAN/DEPLOY/REVIEW + 32 extended),
Obey
Rule enforcement plugin. Save rules with natural language, enforce with 17 lifecycle hooks. Three scopes (glob
Claude Code Audit Gate
Independent audit agent for Claude Code: audits an app built by another agent (OWASP ASVS/Top 10 security, eve
Iac Secopilot
Ask natural-language questions about a Terraform plan and get cited, evaluated answers grounded in the CIS AWS
Skill Lint
Security scanner for Claude Code / agent skills. Catches prompt injection, obfuscation, credential exfiltratio
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat
Related Agents
Appsec Engineer
Application Security Engineer (Tier 3): reviews and tests code against OWASP Top 10:2025 / ASVS — authenticati
Python Security Auditor
Production-grade Python security auditor eliminating os.execv() vulnerability, bare exception handlers, and si
Laravel Security Auditor
Expert in Laravel application security, specializing in vulnerability detection, secure coding practices, auth