A Claude Code skill providing the latest OWASP security best practices (2025-2026) for developers building secure applications.
FAQ
claude-code-owasp is a Claude Code plugin with 1 hand-picked skill for security work, indexed on Flowy. Install it with the command on its page. It includes owasp-security. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
$ npx -y skills add agamm/claude-code-owasp --agent claude-code
Repo: agamm/claude-code-owasp
A Claude Code skill providing the latest OWASP security best practices (2025-2026) for developers building secure applications.
The skill is a directory (SKILL.md plus on-demand reference/ files), so install the whole
folder. The easiest way is degit, which copies a
GitHub subdirectory without the .git history:
npx degit agamm/claude-code-owasp/.claude/skills/owasp-security .claude/skills/owasp-security
Or install globally for all projects:
npx degit agamm/claude-code-owasp/.claude/skills/owasp-security ~/.claude/skills/owasp-security
Location: .claude/skills/owasp-security/
SKILL.md (the always-loaded core):
reference/ (loaded on demand, following Claude Code progressive-disclosure best practices):
languages.md - language-specific security quirks for 20+ languages with unsafe/safe examplesowasp-report.md - deep-dive on the Top 10:2025, ASVS 5.0, the LLM Top 10 (2025), and the Agentic list (2026), with per-item attack vectors and mitigationsCategory names, ASVS chapter structure, and ASVS requirement IDs and levels are verified directly against owasp.org/Top10/2025, github.com/OWASP/ASVS, and genai.owasp.org rather than paraphrased.
This matters more than it sounds: ASVS 5.0 renumbered every chapter, so 4.0 requirement IDs do not carry over, and three Top 10 categories were renamed in 2025. Much of the OWASP material circulating online still cites the old IDs and names.
Once installed, Claude Code automatically activates this skill when you:
"Review this code for security issues"
"Is this authentication implementation secure?"
"What are the security risks in this Python code?"
"Help me implement secure session management"
"Check this AI agent for OWASP agentic risks"
| Standard | Version | Focus |
|---|---|---|
| OWASP Top 10 | 2025 | Web application vulnerabilities |
| OWASP ASVS | 5.0.0 | Security verification requirements |
| OWASP Top 10 for LLM Apps | 2025 | LLM/RAG/tool-calling app risks |
| OWASP Agentic | 2026 | AI agent security risks |
Security quirks for 20+ languages including:
| Web | Systems | Mobile | Scripting |
|---|---|---|---|
| JavaScript/TypeScript | C/C++ | Swift | Python |
| PHP | Rust | Kotlin | Ruby |
| Java | Go | Dart | Perl |
| C# | Shell |
Each language section includes common vulnerabilities, unsafe/safe code patterns, and key functions to watch for.
git clone https://github.com/agamm/claude-code-owasp.git
cp -r claude-code-owasp/.claude/skills/owasp-security YOUR_PROJECT/.claude/skills/
Contributions welcome! Please:
MIT License - See LICENSE file for details.
Keywords: OWASP, security, Claude Code, AI security, application security, ASVS, secure coding, vulnerability, injection, XSS, CSRF, authentication, authorization
.claude/
skills/
owasp-security/
reference/
languages.md
owasp-report.md
SKILL.md
.gitignore
LICENSE
README.mdยฉ 2026 Flowy ยท Free and open source
Built for Claude Code ยท Not affiliated with Anthropic