AI Agent OWASP 安全检查

原名:agent-owasp-compliance

依据 OWASP Agentic Security Initiative 风险检查智能体代码和工具链。

中文 Skills 技能说明

用于上线前的防御性安全审查,覆盖提示注入、工具滥用、身份权限、数据泄露和供应链风险。结论要引用实际代码与配置,不把规则命中直接当成漏洞,也不提供未授权攻击或安全控制绕过。

上游能力依据

上游原始适用说明:Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10 agentic risks - Generating a compliance report for security review or audit - Comparing agent framework security features against the standard - Any request like "is my agent OWASP compliant?", "check ASI compliance", or "agentic security audit"

上游 SKILL.md 主要章节(保留原文标题):

使用边界

先确认授权范围、资产边界和证据来源。输出用于防御性检查与人工决策,不自动执行攻击、绕过或破坏性操作。

作者、翻译与许可证

原作者
GitHub, Inc. 与 awesome-copilot contributors
中文翻译
CEOFans翻译
许可证
MIT
上游来源
https://github.com/github/awesome-copilot/tree/3f0bba475ec40b9680e1d0311b9caffeec5ad4c3/skills/agent-owasp-compliance

适用范围

平台:linux、macos、windows;标签:安全与合规、AI Agent OWASP 安全检查

安全提示

基础静态扫描不等于绝对安全。技能可能调用命令、浏览器、云服务或本地文件,请在最小权限环境中使用,高风险操作必须人工确认。

如发现侵权、许可证或安全问题,可在本页前台提交投诉,管理员复核后可立即下架。