Favicon of owasp-cicd

owasp-cicd Skill

AI Agent SkillPowerShellOpen source

OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks. Published by microsoft in hve-core.

What is owasp-cicd Skill?

OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
77/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Security review use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use owasp-cicd Skill

  • Use it for security review.

Built with

PowerShellCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/hve-core
  • Skill file: .github/skills/security/owasp-cicd/SKILL.md

What it does

OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.

Skill instructions

OWASP® CI/CD Top 10 — Skill Entry This SKILL.md is the entrypoint for the OWASP CI/CD Top 10 skill. The skill encodes the OWASP Top 10 CI/CD Security Risks as structured, machine-readable references that an agent can query to identify, assess, and remediate CI/CD pipeline security risks. Normative references (CI/CD Top 10) 1. 00 Vulnerability Index 2. 01 Insufficient Flow Control Mechanisms 3. 02 Inadequate Identity and Access Management 4. 03 Dependency Chain Abuse 5. 04 Poisoned Pipeline Execution 6. 05 Insufficient PBAC 7. 06 Insufficient Credential Hygiene 8. 07 Insecure System Configuration 9. 08 Ungoverned Usage of 3rd Party Services 10. 09 Improper Artifact Integrity Validation 11. 10 Insufficient Logging and Visibility Skill layout SKILL.md — this file (skill entrypoint). references/ — the CI/CD Top 10 normative documents. 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references. 01 through 10 — one document per vulnerability aligned

Explore related resources

Frequently asked questions

What is owasp-cicd?

owasp-cicd is a open-source AI agent skill with Copy skill directory. OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.

Who is owasp-cicd best for?

owasp-cicd is best for reusing agent instructions, scripts, and references, security review workflows.

How do I install owasp-cicd?

Install or run owasp-cicd using Copy skill directory. Check owasp-cicd for the latest setup command.

Is owasp-cicd actively maintained?

owasp-cicd may need a closer maintenance check before production use.

Share:

Stars
1,263
Forks
229
Last commit
9 days ago
Repository age
9 months
License
MIT

Auto-fetched from GitHub.

Ad
Favicon

 

  
 

Similar to owasp-cicd