A Claude Code skill to design, audit, and review agentic AI systems using the OWASP GenAI Security Project's Agentic AI – Threats and Mitigations (v1.1, December 2025).
The skill encodes the full taxonomy — 17 agentic threats (T1–T17), the threat applicability decision path, and the 6 mitigation playbooks — as an executable workflow with three routes:
| Route | Use for | Deliverable |
|---|---|---|
| Design | New or redesigned agentic systems | Threat model document + testable security requirements |
| Audit | Existing agent codebases/deployments | Audit report with findings, severities, and remediation order |
| Review | PRs, diffs, or single components (tools, MCP servers, memory, prompts) | Review verdict with scoped findings |
Every deliverable includes a coverage matrix: each of the 17 threats gets an explicit verdict (N/A with a capability-based reason, Assessed-OK with evidence, or a Finding), so nothing is skipped silently.
Copy the agentic-security/ directory into your skills folder:
# Project skill (this repo only)
cp -R agentic-security /path/to/your/repo/.claude/skills/
# Personal skill (all projects)
cp -R agentic-security ~/.claude/skills/Then invoke it with /agentic-security, or let it trigger automatically on requests like
"threat model this agent", "audit this MCP integration", or "review this tool change".
agentic-security/
├── SKILL.md # Intake, routing, capability profile (Q1–Q6), severity scale
├── references/
│ ├── threat-taxonomy.md # T1–T17: descriptions, scenarios, code-level indicators
│ ├── mitigation-playbooks.md # 6 playbooks: proactive / reactive / detective controls
│ └── report-templates.md # Threat model, audit report, and review output templates
└── workflows/
├── design.md # Secure-by-design process for new systems
├── audit.md # Full audit of an existing codebase
└── review.md # Targeted change/PR review
T1 Memory Poisoning · T2 Tool Misuse · T3 Privilege Compromise · T4 Resource Overload · T5 Cascading Hallucination Attacks · T6 Intent Breaking & Goal Manipulation · T7 Misaligned & Deceptive Behaviors · T8 Repudiation & Untraceability · T9 Identity Spoofing & Impersonation · T10 Overwhelming Human-in-the-Loop · T11 Unexpected RCE and Code Attacks · T12 Agent Communication Poisoning · T13 Rogue Agents in Multi-Agent Systems · T14 Human Attacks on Multi-Agent Systems · T15 Human Manipulation · T16 Insecure Inter-Agent Protocol Abuse (MCP/A2A) · T17 Supply Chain Compromise
This skill is an adaptation of:
OWASP Top 10 for LLM Apps & Gen AI — Agentic Security Initiative, "Agentic AI – Threats and Mitigations", Version 1.1, December 2025. https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/
The taxonomy, attack scenarios, and mitigation playbooks are derived from that document. The workflow structure, code-level indicators, severity scale, and report templates were added for use as a Claude Code skill. OWASP does not endorse this adaptation.
Like the source document, this work is licensed under CC BY-SA 4.0. See LICENSE.