Skip to main content

security-owasp-web

Stars10
Forks0
UpdatedJuly 5, 2026 at 10:55

Review or design a web, API, or mobile-backend system against the current OWASP Top 10 risk categories, including the 2025 order: broken access control, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design, authentication failures, software or data integrity failures, security logging and alerting failures, and mishandling of exceptional conditions. Produces a per-category status table, evidence list, residual risks, and a remediation plan that maps each finding to a code or configuration owner. Use before any web/API/mobile-backend release, on every major change to auth, data flows, third-party integrations, exception handling, or supply chain, and as a recurring gate alongside qa-eval and pr-review.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
3 files
SKILL.md
readonly