LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: owasp

Browse skills that share this tag.

  • agent-owasp-compliance - Evaluate AI agent codebases for OWASP ASI compliance.
    owaspasisecurity-auditcompliance

    ★ 7 · Updated 2026-09-22

    Evaluates AI agent codebases against OWASP Agentic Security Initiative Top 10 risks and generates gap-focused compliance reports.

    ⚙ Evaluate AI agent codebases⚙ Map controls to ASI risks⚙ Run agentic security audits
  • bola-idor - Broken Object Level Authorization (BOLA/IDOR) Testing
    authorizationbolaidorowasp

    ★ 22 · Updated 2026-09-18

    Identifies and tests Broken Object Level Authorization and Insecure Direct Object Reference vulnerabilities in APIs and web applications.

    ⚙ Map object identifiers across applications⚙ Replay requests using alternate tokens⚙ Test unauthenticated endpoint access
  • llm-security - LLM and AI Agent Security Assessment
    llm-securityai-securityprompt-injectionagent-security

    ★ 1 · Updated 2026-09-16

    Conduct authorized security assessments of LLM applications and AI agents, covering prompt injection, tool abuse, RAG exposure, and supply-chain risks.

    ⚙ Reconnoiter AI attack surfaces⚙ Test prompt injection vulnerabilities⚙ Test tool abuse risks
  • security-review-owasp-dom-based-xss-prevention - OWASP DOM-Based XSS Prevention Security Review
    security-reviewowaspdom-xssxss-prevention

    ★ 0 · Updated 2026-09-16

    Review DOM-based XSS prevention concerns, trust boundaries, and operational assumptions against OWASP guidance.

    ⚙ Identify rendering paths and storage⚙ Trace attacker data to sinks⚙ Validate controls against security checklist
  • claude-pentest-skills - Structured Web Application Penetration Testing
    penetration-testingweb-securityowaspvulnerability-assessment

    ★ 40 · Updated 2026-09-14

    Provides structured web application penetration testing using OWASP methodology, curated payload references, 6-gate validation, and report generation.

    ⚙ Define testing scope and authorization⚙ Map target attack surface⚙ Test target vulnerability classes
  • r00-hesreallyhim-awesome-claude-code--security - Security & Compliance Skill Suite
    securitycompliancegdprsoc2

    ★ 75 · Updated 2026-09-12

    Provides security audits, vulnerability management, GDPR and SOC2 compliance checks, and incident response workflows with 10 specialised commands.

    ⚙ Scan code for OWASP vulnerabilities⚙ Generate dependency CVE reports⚙ Audit GDPR data flow and consent
  • security-audit-triage - Security Audit Triage
    security-auditcvepentestowasp

    ★ 0 · Updated 2026-09-11

    Map pentest reports and CVEs to source code, classify confirmation statuses, evaluate API risks, and prioritize P0/P1 fix scope.

    ⚙ Map pentest reports to code⚙ Classify vulnerability finding status⚙ Assess API security risks
  • owasp-www-project-web-hacking-incident-database - OWASP Web Hacking Incident Database Project Skill
    owaspsecurityrubyprojects-and-frameworks

    ★ 0 · Updated 2026-09-10

    OWASP repository skill focused on security guidance, tooling, and web hacking incident database project content.

    ⚙ Read project documentation and workflows⚙ Inspect manifests and lock files⚙ Implement minimal repository changes
  • owasp-www-project-kubefim - OWASP repository for security guidance and project content
    owaspcloud-securitycontainer-securityruby

    ★ 0 · Updated 2026-09-10

    Provides guidance for updating code, docs, tests, and CI artifacts in the OWASP www-project-kubefim repository.

    ⚙ Read guidelines and workflow files⚙ Inspect manifests and lock files⚙ Implement minimal code changes
  • 007 - Security auditing, threat modeling, and system hardening
    security-auditthreat-modelingowasphardening

    ★ 6 · Updated 2026-09-09

    Performs security audits, threat modeling, OWASP checks, code reviews, incident response, and infrastructure hardening.

    ⚙ Perform security audit analysis⚙ Model threats using STRIDE framework⚙ Review code for security risks
  • exploiting-cross-site-script-inclusion-xssi - Exploiting Cross-Site Script Inclusion (XSSI)
    penetration-testingxssijsonpowasp

    ★ 487 · Updated 2026-06-30

    Identify and exploit Cross-Site Script Inclusion vulnerabilities to read sensitive data from static scripts, dynamic JS, JSONP responses, and non-JS files cross-origin.

    ⚙ find script and JSONP endpoints⚙ detect dynamic JavaScript via cookie diffing⚙ read global variables from included scripts
  • code-reviewer - AI-Powered Code Review Expert
    code reviewstatic analysissecurityperformance

    ★ 4 · Updated 2026-05-28

    Analyze code quality, security, and performance using AI-powered review tools and modern static analysis techniques

    ⚙ analyze code⚙ detect vulnerabilities⚙ review security
  • security-auditor - Code Security Vulnerability Scanner
    securityowaspvulnerabilitiessast

    ★ 602 · Updated 2026-05-11

    Scans codebases for security vulnerabilities and OWASP compliance

    ⚙ scan dependencies⚙ detect secrets⚙ analyze code statically
  • performing-threat-modeling-with-owasp-threat-dragon - Perform Threat Modeling with OWASP Threat Dragon
    cybersecuritythreat-modelingowaspstride

    ★ 4 · Updated 2026-05-09

    Create data flow diagrams, identify threats using STRIDE and LINDDUN, and generate threat model reports

    ⚙ Create data flow diagrams⚙ Identify STRIDE threats⚙ Identify LINDDUN threats
  • performing-threat-modeling-with-owasp-threat-dragon - Threat Modeling with OWASP Threat Dragon
    threat-modelingowaspthreat-dragonstride

    ★ 1 · Updated 2026-05-09

    Create data flow diagrams, identify threats using STRIDE and LINDDUN, and generate threat model reports

    ⚙ create data flow diagrams⚙ identify threats using STRIDE⚙ identify threats using LINDDUN
  • performing-threat-modeling-with-owasp-threat-dragon - OWASP Threat Dragon Threat Modeling
    threat-modelingcybersecuritydevsecopsowasp

    ★ 4 · Updated 2026-05-09

    Create threat models using OWASP Threat Dragon with STRIDE and LINDDUN methodologies

    ⚙ create data flow diagrams⚙ identify threats with STRIDE⚙ identify threats with LINDDUN
  • performing-threat-modeling-with-owasp-threat-dragon - OWASP Threat Dragon Threat Modeling
    threat-modelingowaspcybersecuritydevsecops

    ★ 64 · Updated 2026-05-09

    Create data flow diagrams and identify threats using STRIDE and LINDDUN methodologies

    ⚙ create data flow diagrams⚙ define threat model scope⚙ identify threats
  • https-certificate-checker - Https Certificate Checker - Automated Security Fundamentals
    securityauthenticationvalidationowasp

    ★ 2,781 · Updated 2026-02-12

    Automated HTTPS certificate checking for security fundamentals compliance

    ⚙ check certificate validity⚙ analyze certificate details⚙ generate validation reports
  • code-injection-detector - Automated Code Injection Detection Assistant
    securityauthenticationvalidationowasp

    ★ 2,781 · Updated 2026-02-12

    Provides automated assistance for code injection detection tasks

    ⚙ Provide step-by-step guidance⚙ Follow industry best practices⚙ Generate production-ready code