Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:
OWASP
GitHub 创作者资料

OWASP

按仓库查看 2 个 GitHub 仓库中的 19 个已收集 skills,并展示近似职业覆盖。

已收集 skills
19
仓库
2
职业领域
2
更新
2026-05-23
职业覆盖
该创作者主要覆盖的职业大类。
仓库浏览

仓库与代表性 skills

#001
secure-agent-playbook
18 个 skills788更新于 2026-05-17
占该创作者 95%
agent-security-audit
信息安全分析师

Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. Use when reviewing CLAUDE.md files, MCP configs, agent orchestration code, or any AI agent setup.

2026-05-17
agentic-ai-risk-assess
信息安全分析师

Assess agentic AI applications against the OWASP Top 10 for Agentic Applications 2026. Use when reviewing autonomous AI agents, multi-agent systems, or agentic workflows for security risks including goal hijacking, tool misuse, privilege abuse, and rogue agent behavior.

2026-05-17
llm-risk-assess
信息安全分析师

Comprehensive LLM security assessment against OWASP Top 10 for LLM Applications 2025. Use when reviewing LLM-integrated applications, RAG pipelines, chatbots, AI agents, or GenAI features. Covers prompt injection, data poisoning, supply chain, excessive agency, and more with real-world attack scenarios and testing methodologies.

2026-05-17
mcp-server-review
信息安全分析师

Security review of MCP (Model Context Protocol) server implementations and configurations. Use when auditing MCP server source code, evaluating third-party MCP servers before installation, or reviewing Claude Code MCP integrations for overpermissioning, injection risks, and data exposure.

2026-05-17
prompt-injection-test
信息安全分析师

Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy. Use when red-teaming AI apps, validating guardrails, or deepening LLM01 (Prompt Injection) assessments.

2026-05-17
api-security-review
信息安全分析师

Comprehensive API security review against OWASP API Security Top 10 (2023). Use when reviewing OpenAPI/Swagger specs, auditing REST/GraphQL/gRPC implementations, testing authentication mechanisms, or checking API gateway configurations. Covers BOLA/IDOR, broken auth, mass assignment, rate limiting, SSRF, and more with real-world attack scenarios.

2026-05-17
code-review-security
信息安全分析师

Security-focused code review mapped to OWASP Top 10 and ASVS. Use when reviewing pull requests, auditing files or modules for vulnerabilities, or performing pre-merge security gate checks. Covers injection, auth, authorization, cryptography, data exposure, misconfiguration, and deserialization.

2026-05-17
iac-security-review
信息安全分析师

Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). Use when reviewing IaC files for misconfigurations, overpermissioning, exposed resources, missing encryption, secrets in code, and supply chain risks. Covers CIS benchmarks and cloud security best practices.

2026-05-17
当前展示该仓库 Top 8 / 18 个已收集 skills。
#002
mastg
1 个 skills12.9k2.7k更新于 2026-05-23
占该创作者 5.3%
已展示 2 / 2 个仓库
已展示全部仓库
OWASP GitHub Skills | SkillsMP