Las Vegas, August 17, 2026 — Following Black Hat USA and DEF CON 2026, the OWASP Agentic Skills Top 10 project released version 1.0 of its standard. A skill is a reusable bundle of instructions and resources that an AI agent can find, load, and run on its own. They are now in wide use before anyone agreed on how to check them.
A skill is not much to look at. It is a folder with a SKILL.md file inside — a short metadata header, instructions in plain English, and whatever scripts and resources the job needs. An agent reads it and acts on it. That is the entire mechanism, and that is the problem. The instructions are prose, not code, so tools built to scan code walk straight past them. And the skill runs with the host agent’s permissions, not with permissions of its own. Application security was not built for that, and neither was the LLM guidance written before agents started installing their own tooling.
None of this is hypothetical. In January 2026, the ClawHavoc campaign pushed 1,184 malicious skills from 12 publisher accounts that all reported to the same command-and-control address. Trail of Bits showed how skills slip past scanners. Air documented skill hijacking. A USENIX Security 2026 measurement study analyzed 98,380 skills across public marketplaces and confirmed 157 malicious skills carrying 632 vulnerabilities. A separate 96,096-skill reference corpus, filed as a data contribution to the project repository, reported 751 malware findings. The document cites all of it, with sources.
The ten risks
The ten risks follow a skill from the moment someone writes it — through distribution, installation, execution, updates, and whatever governance catches it along the way. They are written for the people standing at each of those points: the security teams deciding what their organization is allowed to install, the developers building skills, the marketplaces shipping them, and the frontier labs whose agents load and run them.
AST01 — Malicious Skills
AST02 — Supply Chain Compromise
AST03 — Over-Privileged Skills
AST04 — Insecure Metadata
AST05 — Untrusted External Instructions
AST06 — Weak Isolation
AST07 — Update Drift
AST08 — Poor Scanning
AST09 — No Governance
AST10 — Cross-Platform Reuse
Each entry says what the risk is, why it belongs to skills rather than to software in general, what the evidence looks like, and what to do about it. Every one maps to OWASP AISVS v1.0 controls, the OWASP Agentic Security Initiative Top 10, the MCP Top 10, the OWASP Top 10 for LLM Applications, ASVS, CSA MAESTRO, ISO/IEC 42001, and NIST AI RMF, so a team already working against one of those does not have to start from scratch. The document ships working code for signature verification, behavioral sandboxing, dependency pinning, and integrity checking, and proposes a Universal Skill Format manifest so a skill can move between platforms without shedding its provenance on the way.
“Skills moved faster than anyone’s threat model,” said Ken Huang, project leader and CEO of DistributedApps.ai. “We had a distribution channel with npm’s reach and none of npm’s decade of hard-won security infrastructure — no signing, no provenance, no shared vetting between registries. This document is the community writing down what it found, in the open, so that builders and platform operators have something concrete to work from.”
“Spend enough years on the offensive side, and you learn that the best access isn’t an exploit. It’s a legitimate mechanism nobody is watching. Agentic skills are that mechanism right now: plain-language instructions, running with the agent’s permissions, invisible to every tool built to read code. The AST10 is the first framework to treat the behavior layer as an attack surface rather than a configuration detail,” said Rob Joyce, Former NSA Cybersecurity Director and Founder, Joyce Cyber LLC.
“Because skills operate under an agent’s delegated authority, boundary control is vital. The OWASP Agentic Skills Top 10 provides a practical framework for security teams to surface and mitigate skill-level risks, “ said Jason Clinton, former Chrome Infrastructure Security Lead and former Anthropic CISO, Author.
“The OWASP Agentic Skills Top 10 provides the industry with a much-needed security baseline for the emerging agentic ecosystem. As agentic capabilities move rapidly into production, clear guidance on the risks unique to agentic skills and how to address them is essential to building AI systems that organizations can deploy with confidence,” said Apostol Vassilev, Research Manager, NIST.
“This is the rare framework that arrived on time. The skill ecosystem was being poisoned at scale before most organizations had even inventoried what their agents were running. The AST10 gives defenders what was missing: a common language for the behavior layer, grounded in confirmed incidents, with mitigations designed to fail closed instead of failing quietly,” said Omar A. Turner, General Manager, Security, Microsoft.
“Joining forces across the labs, the foundation institutes, the open source community, and the security vendors is the only way our industry can securely build the new layer of software of the agentic era. The Top 10 Skills initiative isn’t about cataloging risks in a markdown file. It’s about how we build a secure ecosystem together - setting the right foundations and infrastructure from the very beginning,” said Niv Hoffman, CTO, Air.
Availability
The Agentic Skills Top 10 v1.0 is available at no cost under the OWASP open license: https://owasp.org/www-project-agentic-skills-top-10/assets/publications/ast10-top10-whitepaper-2.pdf
Video Link: (Subscribe and get daily signal on Agentic AI)
Project leadership
Ken Huang (DistributedApps.ai), project leader. Co-leads: Akram Sheriff (Ex-Cisco Systems, Stealth Startup Founder), Aonan Guan (Wyze), Bhavya Gupta (Stanford University), Fabio Cerullo (OWASP), Hammad Atta (Qorvex Consulting), Iftach Orr (Alice.io), and Niv Hoffman (Air).
Reviewers and contributors
The project thanks the following reviewers and contributors, whose review, evidence, code, and correction shaped this release:
Ken Huang (DistributedApps.ai), Akram Sheriff (Ex-Cisco Systems, Stealth Startup Founder), Ashutosh Barot (CoinDCX), Tymofii Pidlisnyi (Agent Passport System), Manish Kumar Yadav (SAP), Janapareddy Sri Sushmitha (American Express), Nir Paz (NVIDIA), Daniel Alfasi (Reco.ai), Dinesh Kumar P (Nextgen Healthcare), Vandana Verma Sehgal (Snyk), Prateek Kalasannavar (Lenovo), Rajivarnan R (SECNORA), Hammad Atta (Qorvex Consulting), Jaafer Rahmani (University of Freiburg / Hochschule Offenburg), Prasanna Subramanian (Mercedes-Benz), Iftach Orr (Alice.io), Paola Garcia Cardenas (NYU / Gong), Bhavya Gupta (Stanford University), Ed Sewell (VELOCITY AI Security Innovation Center), Lewis Peach (Google Public Sector), Hasan Yasar (Carnegie Mellon University), Dr. Muhammad Zeeshan Baig (Qorvex Consulting), Dr. Yasir Mehmood (Qorvex Consulting), Dr. Muhammad Aziz ul Haq (Qorvex Consulting), Dr. Muhammad Aatif (Qorvex Consulting), Omer Ben Simon (Adversa AI), Tyler Lalicker (Zaun), Jacky Chan (Beever AI / Votee AI), Alex Polyakov (Adversa AI), and Ying-Jung Chen (Georgia Institute of Technology).
With thanks also to Ash Moran, Numan Yilmaz, Vishwas Manral, Zachary Satterly, Angela Sorosina, Mayur Agnihotri, Sebastien Gioria, Yehya Karout, Youssef Harkati, Michael Wilson, Sebastián Vielva, Adam Sah, Jerry Huang (Kleiner Perkins), Ravi Chauhan, Mo Sadek (Alice.io), Carlos Vieira, Christopher Calvani, and Subharthi Kundu.
The project further thanks the many contributors who filed issues and pull requests against the public repository. The complete contribution record, including every pull request and issue by GitHub account, is published in full in section 12 of the document.
Black Hat panels
The project is grateful to the panelists who joined one of two sessions on this work during Black Hat:
Apostol Vassilev, Research Manager, NIST
Michael D’Angelo, Member of Technical Staff, Cyber, OpenAI
Omar Turner, General Manager, Security, Microsoft
Yair Saban, Co-founder and CEO, AIR
Niv Hoffman, Co-founder and CTO, AIR, and project co-lead
Bhavya Gupta, Information Security Officer, Stanford University, and project co-lead
Ken Huang, CEO of DistributedApps.ai, Project Lead, OWASP Agentic Skills Top 10
Their questions and insights, delivered in front of a live audience, sharpened several positions in this release.
About OWASP Agentic Skills Top 10
The OWASP Agentic Skills Top 10 (AST10) is a community-driven OWASP project documenting the ten most critical security risks in agentic AI skills, the packaged instructions that agents load and execute. It is the first framework written specifically for the skill layer, which existing application security tooling does not read as code and therefore does not meaningfully inspect. Version 1.0 covers the major agent ecosystems, including OpenClaw, Claude Code, Cursor and Codex, and VS Code, and names ten risks: malicious skills, supply chain compromise, over-privileged skills, insecure metadata, untrusted external instructions, weak isolation, update drift, poor scanning, missing governance, and cross-platform reuse. Each risk ships with evidence drawn from real campaigns rather than hypotheticals, along with prevention guidance and mitigations teams can apply today.
About OWASP AIVSS Project
The project thanks the OWASP AIVSS leadership — Ken Huang, Michael Bargury, Vineeth Sai Narajala, Bhavya Gupta, and Tim Marple — and the AIVSS Distinguished Review Board for their continued leadership and support for these two Agentic Security Projects, which are becoming a go-to resource in the field. The Agentic Skills Top 10 maps each risk to AISVS v1.0 control IDs, which ask whether a control is implemented. It does not apply AIVSS scoring, which rates how severe a given risk is. AIVSS project: https://aivss.owasp.org/
About OWASP
The OWASP Foundation (Open Worldwide Application Security Project) is a nonprofit that works to improve the security of software. All OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. More at
https://owasp.org
Media contact
Ken Huang, Project Lead, OWASP Agentic Skills Top 10

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.