owasp-security

Review web applications against OWASP standards for security vulnerabilities.

Updated Mar 23, 2026
One-click install
npx skills add https://github.com/disciplin-run-org/jjstack --skill owasp-security-disciplin-run-org
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: owasp-security
Source: https://github.com/disciplin-run-org/jjstack/tree/main/references/owasp-security
Command: npx skills add https://github.com/disciplin-run-org/jjstack --skill owasp-security-disciplin-run-org

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps developers and security professionals identify and mitigate web application vulnerabilities by applying OWASP security standards.

Core Features & Use Cases

  • Security Standards Application: Guides reviews against OWASP Top 10, ASVS, and AI security risks for comprehensive coverage.
  • Code Review Checklist: Provides detailed checklists for input handling, authentication, access control, data protection, and error handling.
  • Use Case: When auditing a web application's codebase, use this Skill to systematically evaluate security controls and ensure compliance with industry best practices.

Quick Start

Use the owasp security skill to review the authentication module for password hashing and session management.

Frequently Asked Questions about owasp-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a secure code review for web application vulnerabilities?

Secure code review for web applications involves systematically evaluating authentication, access control, and input validation against OWASP standards. This skill provides detailed checklists to identify configuration issues and ensure compliance with industry best practices.

What is the OWASP Top 10 checklist for API security and input validation?

The OWASP Top 10 checklist for API security covers input handling, data protection, and error handling to prevent common vulnerabilities. It guides reviews against ASVS and AI security risks to ensure comprehensive coverage of configuration flaws.

Can I audit authentication and session management using OWASP ASVS standards?

Auditing authentication and session management with OWASP ASVS standards requires evaluating password hashing and session controls. This skill applies these security standards to systematically review authentication modules and identify vulnerabilities.

Does this security review approach cover AI agent safety and access control flaws?

This security review approach covers AI agent safety and access control flaws by applying OWASP standards to identify agent security risks. It evaluates input validation and access control configurations to mitigate web application vulnerabilities.

What's the best way to identify secure coding patterns and configuration issues in a codebase?

Identifying secure coding patterns and configuration issues requires applying a detailed code review checklist for data protection and error handling. This skill helps systematically evaluate security controls to ensure compliance with OWASP best practices.