Test against the OWASP Top 10 The OWASP Top 10 is a taxonomy of risk categories, not a test suite — "OWASP Top 10 testing" means exercising each category against the real application and reporting what's actually exploitable. Strix's agents do the exploitation; this skill covers running it category-by-category and reporting coverage honestly. Use the current edition: OWASP Top 10:2025 (8th installment, superseding 2021). Ask the user before targeting an older edition — some compliance checklists still reference 2021, and a report labelled with the wrong edition is misleading. Key differences from 2021: SSRF is folded into A01 , A03 Software Supply Chain Failures expands the old "Vulnerable and Outdated Components", and A10 Mishandling of Exceptional Conditions is new; A02 Security Misconfiguration moved 5→2. Install, LLM setup, and the managed-cloud alternative: penetration-testing-with-strix . What is and is not testable by an agent Be straight with the user about this — claiming a clean sweep of all ten is misleading. Show more Installs 926 Repository usestrix/strix GitHub Stars 57.8K First Seen 5 days ago Security Audits Gen Agent Trust Hub Pass Socket Warn Snyk Fail
owasp-top-10-testing
安装
npx skills add https://github.com/usestrix/strix --skill owasp-top-10-testing