What problem does it solve?
This Skill brings OWASP Top 10:2025, ASVS 5.0, and Agentic AI security guidance into every code review so authentication, authorization, input handling, error responses, and AI agent behavior are assessed with the same rigor as formal security audits.
Core Features & Use Cases
- OWASP Top 10:2025 alignment: Follow the updated OWASP categories to catch broken access control, injection, misconfigurations, logging gaps, and other critical web application risks.
- ASVS 5.0 and Agentic AI coverage: Differentiate requirements across Level 1 through Level 3, enforce password, session, and cryptographic controls, and apply agentic safety checks for goal hijacks, tool misuse, and rogue agents.
- Language-specific footguns and mindset: Reference the key pitfalls for JavaScript, Python, Java, C#, PHP, Go, Ruby, Rust, Swift, Kotlin, C/C++, Scala, R, Perl, Shell, Lua, Elixir, Dart, PowerShell, SQL, and any other language you encounter to avoid known CVEs and memory or serialization traps.
- Use Case: When reviewing a new API endpoint or AI agent workflow, run through the checklists to validate sanitization, scoped credentials, fail-closed logic, and secure deployment practices before approving the merge.
Quick Start
Apply the OWASP Top 10:2025, ASVS 5.0, and Agentic AI security checklists to the targeted code review before merging.