owasp-reference

Map security findings to OWASP category IDs and names.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill owasp-reference
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: owasp-reference
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/security-knowledge/skills/owasp-reference
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill owasp-reference

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps users quickly identify the correct OWASP category for a security finding, making it easier to tag findings, scope reviews, and align reports across different appsec/genai plugins.

Core Features & Use Cases

  • OWASP Family Mapping: Automatically maps a finding to the correct OWASP family (Web, API, LLM, Mobile) and category ID/name.
  • Consistent Reference: Ensures consistent reference across web, API, LLM, and mobile appsec reviews and reports.
  • Use Case: When analyzing a security finding, use this Skill to quickly determine its OWASP category ID and name, facilitating accurate tagging and scoping.

Quick Start

Use the owasp-reference skill to find the OWASP category for a finding: /owasp-reference:find-category "broken access control"

Frequently Asked Questions about owasp-reference

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map a security finding to the correct OWASP category?

To map a security finding to an OWASP category, the Skill identifies the finding and automatically matches it to the corresponding OWASP family Web API LLM or Mobile category ID and name for consistent tagging.

What OWASP Top 10 lists are supported for security finding categorization?

Security finding categorization supports Web API LLM and Mobile OWASP Top 10 lists. It maps findings to the correct OWASP family category ID and name ensuring consistent reference across appsec reviews.

Can I use this to ensure consistent OWASP reference tags across API and LLM appsec reviews?

Yes you can ensure consistent OWASP reference tags across API and LLM appsec reviews. The Skill aligns reports by mapping findings to standard OWASP category IDs and names across web API LLM and mobile contexts.

What is the best way to find the OWASP category ID for broken access control?

The best way to find the OWASP category ID for broken access control is to use the find-category function. It processes the finding description and returns the exact OWASP category ID and name for accurate tagging.

Why do I need an OWASP category mapping tool for security findings?

You need an OWASP category mapping tool to quickly determine the correct category ID and name for security findings. This facilitates accurate tagging scopes reviews effectively and aligns reports across different appsec plugins.