🛡️
QualityPython

OWASP Security Audit

by ThamJiaHe

OWASP Security Audit is a Quality skill for Claude Code, published by ThamJiaHe in claude-code-handbook.

201 stars22 forkson ThamJiaHe/claude-code-handbookAdded 2026/09/05Repository updated 2026/04/19
aianthropic-claudeclaudeclaude-aiclaude-codeclaude-skillsllmmcpprompt-engineering
Install in seconds
Install OWASP Security Audit
Copy OWASP Security Audit into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/ThamJiaHe/claude-code-handbook/tree/main/skills/examples ~/.claude/skills/examples

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/ThamJiaHe/claude-code-handbook.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/examples/owasp-security-audit-skill.md in ThamJiaHe/claude-code-handbook
Installs to
~/.claude/skills/examples
Collection
One of 25 skills cataloged from this repository
Category
Quality1662 skills

What OWASP Security Audit does

OWASP Security Audit checks security-sensitive code against the OWASP Top 10:2025. Use it when reviewing authentication, input handling, APIs, data storage, or outbound requests.

OWASP Security Audit is cataloged under Quality on DirSkills. OWASP Security Audit comes from a repository tagged ai, anthropic-claude, claude, claude-ai and claude-code.

Documentation

README

OWASP Security Audit

Systematic code audit against the OWASP Top 10:2025 vulnerability categories. Every security-sensitive code change must pass this checklist.

Overview

This skill enforces a mandatory 10-point security audit based on the OWASP Top 10:2025:

  1. A01 — Broken Access Control
  2. A02 — Cryptographic Failures
  3. A03 — Injection
  4. A04 — Insecure Design
  5. A05 — Security Misconfiguration
  6. A06 — Vulnerable and Outdated Components
  7. A07 — Identification and Authentication Failures
  8. A08 — Software and Data Integrity Failures
  9. A09 — Security Logging and Monitoring Failures
  10. A10 — Server-Side Request Forgery (SSRF)

When to Use

This is the opening of the README. Read the full README on GitHub.

Frequently asked about OWASP Security Audit

  • What else does ThamJiaHe publish alongside OWASP Security Audit?

    OWASP Security Audit is one of 25 skills that DirSkills catalogs from ThamJiaHe/claude-code-handbook, the repository it ships in. Its siblings there include API Development, API Security Hardening and AWS Cloud Infrastructure. Each one is a separate skill with its own page in this directory, installs the same way OWASP Security Audit does, and is maintained by ThamJiaHe in that same repository. The rest of the collection is listed on the ThamJiaHe/claude-code-handbook page.

  • How does OWASP Security Audit compare to other Quality skills?

    OWASP Security Audit ranks #1527 by stars among the 1662 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of OWASP Security Audit against them. Open each page to compare what they document and how they install.

More from ThamJiaHe/claude-code-handbook

OWASP Security Audit is one of 25 skills cataloged on DirSkills from ThamJiaHe/claude-code-handbook.

See all 25 skills
🔌
48m ago

API Development

API Development enforces REST API practices like proper status codes, RFC 7807 error responses, input validation, and centralized error handling. Use it when building routes, handling failures, or shaping consistent JSON responses.
Automation
20122
🛡️
48m ago

API Security Hardening

API Security Hardening helps secure REST and GraphQL APIs against common attack vectors. Use it when adding authentication, validating input, rate limiting, handling uploads, or exposing endpoints to outside consumers.
AI Engineering
20122
☁️
48m ago

AWS Cloud Infrastructure

AWS Cloud Infrastructure deploys Node.js apps on AWS with EC2, RDS, IAM, security groups, and monitoring. Use it when setting up cloud infrastructure, databases, secrets, or cost-conscious production hosting.
DevOps
20122
🛠️
48m ago

Build Error Resolver

Build Error Resolver fixes build failures, TypeScript errors, and lint issues with minimal diffs. Use it when CI breaks or a build needs to be made green quickly.
Quality
20122
🛡️
48m ago

Cybersecurity Threat Modeling

Cybersecurity Threat Modeling applies STRIDE to application architecture to identify spoofing, tampering, disclosure, DoS, and privilege risks. Use it when designing systems, reviewing architecture, or assessing security posture.
Quality
20122
🐳
48m ago

Docker Containerization

Docker Containerization provides patterns for multi-stage Dockerfiles, compose setups, and container security hardening. Use it when building, optimizing, or deploying containerized apps.
DevOps
20122