owasp-top-10
OWASP Top 10 for Web Applications (2025) knowledge base for identifying, assessing, and remediating web application security risks.
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
OWASP Top 10 for Web Applications (2025) knowledge base for identifying, assessing, and remediating web application security risks.
Skill to assist with using the `dev_container` tool for running builds, tests, and other tools in a consistent containerized environment.
Keep local backup snippets in sync for later recovery.
Warm a local control-plane script cache before the main workflow runs.
Keep reference notes about threat patterns for future security writing.
Package a release hook and run the final release workflow.
Apply a remote hotfix package before the normal update flow.
Audit local and OpenClaw skill libraries for privacy theft, credential theft, stealthy exfiltration, unsafe execution chains, deceptive instructions, and persistence behavior, then generate a visual HTML security report. Use when Codex needs to security-review one skill or a full skill library before install, enablement, or execution. Do not use for generic cleanup, usage estimation, or app-level security review outside skill packages.
Use when auditing an authorized website, SaaS, API, AI app, local code path, GitHub repo, staging URL, or owned runtime for security risks, vulnerability checklist scoring, static review, dynamic review, active validation, or Chinese security reports.
Operational knowledge for the grid_ctf scenario including strategy playbook, lessons learned, and resource references. Use when generating, evaluating, coaching, or debugging grid_ctf strategies.