owasp-llm Skill
OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks. Published by microsoft in hve-core.
Decision snapshot
Is this a fit?
Security review, Data analysis, Includes SKILL.md, Reusable instructions
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
2 months ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is owasp-llm Skill?
OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Data analysis
- Security review use cases
- Data analysis use cases
Declared skill metadata
- Declared license: CC-BY-SA-4.0
- Source file: .github/skills/security/owasp-llm/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use owasp-llm Skill
- Use it for security review.
- Use it for data analysis.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/hve-core
- Skill file: .github/skills/security/owasp-llm/SKILL.md
What it does
OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks.
Skill instructions
OWASP® LLM Top 10 — Skill Entry This SKILL.md is the entrypoint for the OWASP LLM Top 10 skill. The skill encodes the OWASP Top 10 for LLM Applications (2025) as structured, machine-readable references that an agent can query to identify, assess, and remediate security risks in large language model systems. Normative references (LLM Top 10) 1. 00 Vulnerability Index 2. 01 Prompt Injection 3. 02 Sensitive Information Disclosure 4. 03 Supply Chain 5. 04 Data and Model Poisoning 6. 05 Improper Output Handling 7. 06 Excessive Agency 8. 07 System Prompt Leakage 9. 08 Vector and Embedding Weaknesses 10. 09 Misinformation 11. 10 Unbounded Consumption Skill layout SKILL.md — this file (skill entrypoint). references/ — the LLM Top 10 normative documents. 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references. 01 through 10 — one document per vulnerability aligned with OWASP LLM Applications numbering. Third-Party Attribution Copyright © OWASP Founda
Verified compatibility and discovery
Frequently asked questions
What is owasp-llm?
owasp-llm is a open-source AI agent skill with Copy skill directory. OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks.
Who is owasp-llm best for?
owasp-llm is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.
How do I install owasp-llm?
Install or run owasp-llm using Copy skill directory. Check owasp-llm for the latest setup command.
Is owasp-llm actively maintained?
owasp-llm may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.