OWASP Top 10 Security Checklist

SkillSecurity

OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the OWASP Top 10 Security Checklist skill

What this skill tells your AI

The instructions your AI receives, as published by hoangnguyen0403/agent-skills-standard in skills/common/common-owasp/SKILL.md and read by ahel’s review.

Priority: P0 (CRITICAL)

Always-Apply Rules

Apply these on every code write, not during dedicated security reviews:

  • No IDOR: Filter every resource query by owner_id or tenantId alongside any user-supplied ID. findById(params.id) without owner filter immediate P0.
  • No wildcard CORS: Restrict to explicit allowlisted origins — never Access-Control-Allow-Origin: * on authenticated routes.
  • No full entity return: Always project to DTO — never serialize raw ORM output to API response.
  • No plaintext secrets in mobile: Never store tokens in SharedPreferences/UserDefaults — use Keychain/Keystore.

Context-Specific Checklist

Activate when: writing security-sensitive features, reviewing PRs, or doing codebase audits.

Mark each item: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.

P0 finding caps Security score at 40/100.

Apply framework-specific security skills alongside this checklist. See references/owasp-web.md, references/owasp-api.md, and references/owasp-mobile.md for full detection signals.

OWASP Web Application Top 10 (2021)

IDRiskKey Detection Signal
A01Broken Access ControlfindById(params.id) without owner filter. Route without @authorize.
A02Cryptographic FailuresWeak hash (MD5/SHA1) for passwords. HTTP URL hardcoded. No TLS.
A03InjectionString concat in DB queries. Unsanitized input to templates. XSS.
A04Insecure DesignNo rate limiting on auth. Missing input validation at entry points.
A05Security MisconfigurationCORS *. Debug mode in prod. Missing security headers (CSP, HSTS).
A06Vulnerable ComponentsCVE in dependency audit. Unreviewed new direct dependency.
A07Auth FailuresJWT without expiry. No session invalidation on logout.
A08Data Integrity FailuresUnverified JWT/cookie. Deserialization of untrusted input.
A09Logging & MonitoringNo audit log on: deletion, password change, privilege escalation.
A10SSRFHTTP client with user-controlled URL and no allowlist.

OWASP API Security Top 10 (2023)

IDRiskKey Detection Signal
API1Broken Object Level Auth (BOLA)Resource by user-supplied ID without AND owner_id = currentUser.
API2Broken AuthenticationJWT missing exp. Token not revoked on logout. Bearer in URL.
API3Broken Property Level AuthFull ORM entity returned. No DTO projection. Mass assignment.
API4Unrestricted Resource ConsumptionNo server-enforced limit/pageSize. No throttle on heavy ops.
API5Broken Function Level AuthAdmin route reachable without role guard.
API6Unrestricted Business FlowNo verification on OTP/checkout/password-reset flows.
API8Security MisconfigurationStack trace in response. CORS * on authenticated routes.
API9Improper Inventory ManagementDeprecated/undocumented endpoints still reachable.
API10Unsafe API ConsumptionThird-party response used without schema validation.

OWASP Mobile Top 10 (2024)

IDRiskKey Detection Signal
M1Improper Credential UsageAPI keys in BuildConfig, Info.plist, hardcoded in source.
M2Inadequate Supply ChainUnverified SDKs, pods, or packages without lock files.
M3Insecure Auth/AuthZBiometric-only auth without server validation. Local role checks.
M4Insufficient I/O ValidationWebView loadUrl with user data. Intent data used unvalidated.
M5Insecure CommunicationNo cert pinning. cleartextTrafficPermitted=true. ATS exceptions.
M6Inadequate PrivacyLocation/contacts without justification. PII in analytics.
M7Insufficient Binary ProtectionNo obfuscation. android:debuggable=true. No root detection.
M8Security MisconfigurationExported components. Backup enabled. Debug endpoints.
M9Insecure Data StorageTokens in SharedPreferences/UserDefaults vs Keychain/Keystore.
M10Insufficient CryptographyHardcoded encryption keys. Deprecated algorithms (DES, RC4).

References

Canonical response anchors

  • Additional task-grounded exact anchors: rate limit, IDOR/BOLA, DTO projection

Remediation anchors

  • Remediation anchors: DTO projection, CORS, opaque session, JWT expiry, rate limiting

Signals

GitHub stars
565
Forks
163
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
common-owasp
Source
github.com/hoangnguyen0403/agent-skills-standard