Search: "OWASP"

Showing 24 of 25 results

Development

Code Review Agent

Skill · by william yaohui

Comprehensive code review with security, performance, and style analysis for Python, TypeScript, and Go. Detects OWASP Top 10 vulnerabilities, N+1 queries, race conditions, and logic errors before they reach production.

Development ClawHub

agent-owasp-compliance

Agent

# Agent OWASP ASI Compliance Check Evaluate AI agent systems against the OWASP Agentic Security Initiative (ASI) Top 10 — the industry standard for agent security posture. ## Overview The OWASP ASI Top 10 defines the critical security risks specific to autonomous AI agents — not LLMs, not chatbots, but agents that call tools, access systems, and act on behalf of users. This skill checks whether your agent implementation addresses each risk. ``` Codebase → Scan for each ASI control: ASI-01: Prompt Injection

Development ClawHub

owasp-security-check

Skill

# OWASP Security Check Comprehensive security audit patterns for web applications and REST APIs. Contains 20 rules across 5 categories covering OWASP Top 10 and common web vulnerabilities. ## When to Apply Use this skill when: - Auditing a codebase for security vulnerabilities - Reviewing user-provided file or folder for security issues - Checking authentication/authorization implementations - Evaluating REST API security - Assessing data protection measures - Reviewing configuration and deployment settings

Development ClawHub

owasp-security

Skill

# OWASP Security Best Practices Skill Apply these security standards when writing or reviewing code. **Reference files** (load on demand): - [`reference/languages.md`](reference/languages.md) — per-language security quirks with unsafe/safe examples for 20+ languages. - [`reference/owasp-report.md`](reference/owasp-report.md) — comprehensive deep-dive on every OWASP 2025–2026 standard. ## Quick Reference: OWASP Top 10:2025 | # | Vulnerability | Key Prevention | |---|---------------|----------------| | A01 |

Development ClawHub

OWASP Security Code Review

Skill

Performs automated, severity-rated security audits based on OWASP Top 10 (2025) to identify code vulnerabilities, insecure configs, dependency flaws, and sec...

Development ClawHub

SkillGuard - OWASP ASI Agent安全扫描器

Agent

Agent技能安全扫描器 — 上传Skill包自动检测安全漏洞(prompt注入/凭证泄露/代码执行/依赖审计等8维检测)。三平台首发,零依赖Python标准库。

Development ClawHub

Security Audit Pro

Skill

Full OWASP, Nmap, Nikto vulnerability assessment for OpenClaw deployments. Scan your infrastructure, harden configs, and generate compliance reports.

Development ClawHub

Cyber OWASP Review

Skill

Map application security findings to OWASP Top 10 categories and generate remediation checklists. Use for normalized AppSec review outputs and category-level...

Development ClawHub

Locking Down Agent Commerce: The OWASP-Aligned Security Guide for Autonomous AI Agents on GreenHelix

Agent

Locking Down Agent Commerce: The OWASP-Aligned Security Guide for Autonomous AI Agents on GreenHelix. Practical security hardening for AI agents handling rea...

Development ClawHub

OWASP Top 10 AI

Agent

RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for OpenClaw agents. Covers all 10 OWASP LLM risks: prompt...

Development ClawHub

Agent BOM Compliance

Agent

🏛️ Comprehensive compliance engine for AI agents. Evaluate against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS, and more. Generate SBOMs and compliance reports automatically.

Development ClawHub

Phy Websocket Audit

Skill

WebSocket security auditor. Scans source code for 10 WebSocket-specific vulnerabilities — plaintext ws:// connections, missing Origin header validation (CSWS...

Development ClawHub

Phy Xss Audit

Skill

Cross-Site Scripting (XSS) static vulnerability scanner (OWASP A03:2021). Detects reflected, stored, and DOM-based XSS in JavaScript/TypeScript, React, Vue,...

Development ClawHub

Phy Deserialization Audit

Skill

Unsafe deserialization vulnerability scanner (OWASP A08:2021). Detects Python pickle/yaml/eval, Java ObjectInputStream/XStream/XMLDecoder, PHP unserialize, R...

Development ClawHub

Phy Ssrf Audit

Skill

Server-Side Request Forgery (SSRF) vulnerability scanner (OWASP A10:2021). Detects URL-fetching sinks in Python/Java/Node.js/PHP/Go/Ruby that accept user-con...

Development ClawHub

Phy Crypto Audit

Skill

Weak cryptography detector (OWASP A02:2021 — Cryptographic Failures). Scans Python, JavaScript/TypeScript, Go, Java, and PHP source code for 10 classes of in...

Development ClawHub

Phy Path Traversal Audit

Skill

Path traversal and Local File Inclusion (LFI) vulnerability scanner (OWASP A01:2021). Detects user-controlled paths passed to file system sinks in Python/Jav...

Development ClawHub

Blindoracle Fixed

Agent

Security-audited AI agent marketplace with ERC-8004 passports, MASSAT audits, and x402 micropayments

Development ClawHub

Massat Security Audit

Agent

Security audit for multi-agent AI systems - OWASP ASI01-ASI10

Development ClawHub

Security Auditor

Skill

Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.

Development ClawHub

Security Audit Toolkit

Skill

Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.

Development ClawHub

Web漏洞评估(免费版)

Skill

基于OWASP Top 10:2021标准,覆盖19类漏洞及100+检查项,支持多技术栈,提供安全检查清单与修复建议,生成按严重度排序的评估报告。

Development ClawHub

漏洞扫描器(免费版)

Skill

基于OWASP 2025的免费静态分析工具,支持供应链安全、密钥检测、高危代码模式识别及风险优先级排序。

Development ClawHub

Performance Security Assessor

Skill

评估系统性能指标和安全风险,覆盖响应时间、并发能力、资源消耗、OWASP Top 10安全风险等维度,输出量化评估结论和修复建议。当用户需要性能评估、安全评估、渗透测试检查、系统风险评估、安全审计时使用此技能。

Development ClawHub

Perf Security Assessment

Skill

对系统进行性能评估(响应时间、并发能力、资源消耗)和安全评估(认证授权、数据保护、OWASP Top 10),输出性能指标达标情况和安全风险清单。