OWASP Security Checklist
Structured checklist for web application security review. Based on OWASP Top 10. Applied during code review and security audits. AI-specific risks appended. The full operational checklist lives in thesecurity-patterns skill (preloaded into security-auditor). This page is the reference copy for the wiki.
This page is the hub. The checklist was split on 2026-10-04 into topical pages so each stays small and indexable; the 31 OWASP cheat-sheet sources are distributed across them by topic (not as per-claim citations):
- OWASP Top 10 Checklist — A01-A10 review checklist (14 sources)
- OWASP AI and Agent Security Risks — indirect prompt injection, sandbox controls, tool/memory security, AI coding tool threats, denial of wallet (6 sources)
- OWASP Web Security Reference — session management, CSRF, DOM XSS, IDOR, transaction authorization, third-party scripts, deserialization, DoS (11 sources)
Severity Classification
Related Pages
- Indirect Prompt Injection — AI-specific attack vector; primary threat for agents; full prompt injection taxonomy
- Agentic Sandbox Controls — OS-level controls for agent execution environments
- AI Code Review — broader code review process including security as one layer
- Agentic Sandbox Controls — NVIDIA AI Red Team OS-level controls; subprocess escape problem; secret injection pattern
- Error Budget (Agentic) — token/session budget patterns implementing spend limits and circuit breakers