owasp-top-10 by nickcrew/claude-ctx-plugin
npx skills add https://github.com/nickcrew/claude-ctx-plugin --skill owasp-top-10基于 OWASP Top 10 2021,提供识别、预防和修复最关键 Web 应用程序安全风险的专家指导。
按风险严重程度排序:
加载每个漏洞的详细指南:
| 漏洞 | 参考文件 |
|---|---|
广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
skills/owasp-top-10/references/broken-access-control.md |
| 加密机制失效 | skills/owasp-top-10/references/cryptographic-failures.md |
| 注入 | skills/owasp-top-10/references/injection.md |
| 不安全的设计 | skills/owasp-top-10/references/insecure-design.md |
| 安全配置错误 | skills/owasp-top-10/references/security-misconfiguration.md |
| 易受攻击的组件 | skills/owasp-top-10/references/vulnerable-components.md |
| 认证失败 | skills/owasp-top-10/references/authentication-failures.md |
| 完整性故障 | skills/owasp-top-10/references/integrity-failures.md |
| 日志记录与监控 | skills/owasp-top-10/references/logging-monitoring.md |
| SSRF | skills/owasp-top-10/references/ssrf.md |
| 预防策略 | skills/owasp-top-10/references/prevention-strategies.md |
| 评估工作流程 | skills/owasp-top-10/references/assessment-workflow.md |
SAST (静态) : SonarQube, Semgrep, ESLint 安全插件 DAST (动态) : OWASP ZAP, Burp Suite SCA (依赖项) : npm audit, Snyk, Dependabot 密钥扫描 : GitGuardian, TruffleHog 渗透测试 : Metasploit, Kali Linux 工具
周安装量
303
代码仓库
GitHub 星标数
12
首次出现
2026 年 1 月 24 日
安全审计
安装于
opencode285
gemini-cli269
codex264
cursor259
github-copilot256
claude-code243
Expert guidance for identifying, preventing, and remediating the most critical web application security risks based on OWASP Top 10 2021.
Ranked by Risk Severity:
Load detailed guidance for each vulnerability:
| Vulnerability | Reference File |
|---|---|
| Broken Access Control | skills/owasp-top-10/references/broken-access-control.md |
| Cryptographic Failures | skills/owasp-top-10/references/cryptographic-failures.md |
| Injection | skills/owasp-top-10/references/injection.md |
| Insecure Design | skills/owasp-top-10/references/insecure-design.md |
| Security Misconfiguration | skills/owasp-top-10/references/security-misconfiguration.md |
SAST (Static) : SonarQube, Semgrep, ESLint security plugins DAST (Dynamic) : OWASP ZAP, Burp Suite SCA (Dependencies) : npm audit, Snyk, Dependabot Secrets Scanning : GitGuardian, TruffleHog Penetration Testing : Metasploit, Kali Linux tools
Weekly Installs
303
Repository
GitHub Stars
12
First Seen
Jan 24, 2026
Security Audits
Gen Agent Trust HubPassSocketPassSnykPass
Installed on
opencode285
gemini-cli269
codex264
cursor259
github-copilot256
claude-code243
React 组合模式指南:Vercel 组件架构最佳实践,提升代码可维护性
105,000 周安装
| Vulnerable Components | skills/owasp-top-10/references/vulnerable-components.md |
| Authentication Failures | skills/owasp-top-10/references/authentication-failures.md |
| Integrity Failures | skills/owasp-top-10/references/integrity-failures.md |
| Logging & Monitoring | skills/owasp-top-10/references/logging-monitoring.md |
| SSRF | skills/owasp-top-10/references/ssrf.md |
| Prevention Strategies | skills/owasp-top-10/references/prevention-strategies.md |
| Assessment Workflow | skills/owasp-top-10/references/assessment-workflow.md |