OWASP Agentic Skills Top 10
The OWASP Agentic Skills Top 10 (AST10) ranks the ten most critical security risks in AI agent 'skills' — reusable, named workflows that let agents such as OpenClaw, Claude Code, and Cursor chain tool calls into autonomous multi-step tasks.
OWASP incubated it at its March 2026 Oslo Project Summit; author Ken Huang publicly launched AST10 as an OWASP Incubator Project on March 31, 2026, weeks after Snyk's ToxicSkills audit scanned 3,984 ClawHub and skills.sh skills, found 36.8% flawed, and confirmed 76 malicious payloads circulating in the wild.
Think of it as a food-safety inspection for AI agent skills — checking the recipe someone else wrote, not just the ingredients.
See nascent terms 7 days before everyone, unlock every stage filter, and get weekly early alerts.
Why is it emerging now?
OWASP incubated the Agentic Skills Top 10 at its March 2026 Oslo summit and Ken Huang launched it publicly on March 31, weeks after Snyk's ToxicSkills audit found 36.8% of 3,984 scanned OpenClaw skills flawed and the Q1 ClawHavoc campaign planted malicious skills on ClawHub, the primary skill marketplace.
Search Interest
-
Nascent0–7 days
-
Emergent8–30 days
-
Validating31–90 days
-
Rising ← now91–180 days
-
Established180 days +
Outlook
6-month signal projection and commercial timeline.
Security vendors already map products to OWASP's Agentic Top 10; AST10 rides the same wave if its Q4 2026 v1.0 lands on schedule.
Risk · Four overlapping OWASP AI lists (LLM, Agentic Applications, MCP, AST10) risk diluting mindshare and confusing buyers on which to adopt.
Analogs · OWASP Top 10 for LLM Applications · OWASP MCP Top 10 · npm supply-chain audits
-
nowFoundation phase live
AST01-06 published, repo and OWASP page up, no v1.0 yet.
-
3-6moAST07-10 + skill format land
Q3 2026 completion; Universal Skill Format v1.0 release candidate ships.
-
6-12mov1.0 + flagship push
Q4 2026 release, RSA and OWASP AppSec conference debut target flagship status.
Competition & Opportunity for term “OWASP Agentic Skills Top 10”
Signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Heuristic except where marked measured (Google KD).
Ideas for term “OWASP Agentic Skills Top 10”
Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.
No article yet disambiguates the new skill-layer AST10 from OWASP's older, broader Agentic Applications Top 10 — a high-intent confusion query given near-identical branding.
Step-by-step tutorial mapping AST01-AST10 to concrete scans; almost no hands-on walkthroughs exist while the standard is still in its foundation phase.
One explainer per AST01-AST10 code captures long-tail searches for each risk name individually, evergreen as the spec matures.
Static + dynamic checks against a ClawHub or skills.sh package before install, flagging AST01-10 violations; no independent OSS scanner exists outside Snyk's proprietary tool.
CLI that validates and cryptographically signs skills against AST10's proposed YAML spec, including default-deny for SOUL.md/MEMORY.md identity files.
Comparison site tracking which skill-management platforms (Snyk, Tessl, others) already scan against AST10; the category doesn't exist yet.
Screen-recorded demo of AST01 malicious-skill detection using the 13% critical-flaw stat as the hook; visually dramatic and shareable.
Snyk found a critical flaw in 13% of the 'skills' your coding agent just installed without asking — OWASP only wrote a checklist for it in March.
OWASP's own roadmap puts AST10 on the RSA 2026 stage by Q4 — compliance teams that ignore it now will be scrambling in December.
OpenClaw's skill marketplace just had its left-pad moment — except the payload steals credentials instead of breaking a build.
What People Search
Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.
SERP of term “OWASP Agentic Skills Top 10”
What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.
FAQ
What is OWASP Agentic Skills Top 10?
The OWASP Agentic Skills Top 10 (AST10) ranks the ten most critical security risks in AI agent 'skills' — reusable, named workflows that let agents such as OpenClaw, Claude Code, and Cursor chain tool calls into autonomous multi-step tasks.
Why is OWASP Agentic Skills Top 10 emerging now?
OWASP incubated the Agentic Skills Top 10 at its March 2026 Oslo summit and Ken Huang launched it publicly on March 31, weeks after Snyk's ToxicSkills audit found 36.8% of 3,984 scanned OpenClaw skills flawed and the Q1 ClawHavoc campaign planted malicious skills on ClawHub, the primary skill marketplace.
When did OWASP Agentic Skills Top 10 emerge?
Publicly emerged around 2026-03-31 (about 133 days ago as of 2026-08-11). EarlyTerms first recorded a pipeline signal on 2026-07-29.
Related Terms
Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.
- Part of Agentic AI Agentic AI names a class of AI systems that autonomously plan, decide, and take actions to meet user-defined goals — not single-shot… →
- Related OpenClaw Skills OpenClaw Skills is the registry-backed extension system for OpenClaw: a CLI (`openclaw skills install <slug>`) that discovers, installs,… →
- Related ClawHub ClawHub is the public skill registry and marketplace for OpenClaw, the self-hosted personal AI agent. →
- Related OpenClaw OpenClaw is an open-source self-hosted personal AI agent: a long-running runtime that connects to any LLM (Claude, GPT, DeepSeek, Kimi,… →
- Related MCP Server An MCP server is a small, standalone program that exposes one capability — a database, a filesystem, a security scanner, a trading API —… →
- Related MCP Tool An MCP tool is one executable function exposed by an MCP server to a language model over JSON-RPC, defined by a name, description, and… →
- Related Model Context Protocol Model Context Protocol (MCP) is an open, JSON-RPC-2.0-based standard that defines how AI applications talk to external tools, data, and… →
- Related AI Agent Identity AI Agent Identity is the emerging set of protocols and file formats that let an autonomous agent prove who it is, what it's authorized… →
- Related agent traps "Agent traps" is the shorthand English phrase that maps one-to-one to AI Agent Traps, the taxonomy Google DeepMind published on March… →
- Related
Sources
Primary URLs this report cites — open any to verify the claim yourself.
- 01 Ken Huang — Exciting Announcement: OWASP Agentic Skills Top 10 kenhuangus.substack.com ↗
- 02 OWASP — Agentic Skills Top 10 project page owasp.org ↗
- 03 GitHub — OWASP/www-project-agentic-skills-top-10 github.com ↗
- 04 Snyk — ToxicSkills: malicious AI agent skills on ClawHub snyk.io ↗
- 05 Ken Huang — From Oslo to Action: How the OWASP Agentic Skills Top 10 Was Born kenhuangus.substack.com ↗
- 06 Hacker News — Show HN: Mcploitable news.ycombinator.com ↗
- 07 OWASP GenAI Security Project — Top 10 Risks for Agentic AI Security (sibling initiative) genai.owasp.org ↗