OWASP Agentic Skills Top 10

Skills have become a popular way to give agents new abilities, and they introduce supply chain and injection risks similar to plugins and packages. The project gives builders and buyers a shared reference for those risks.

Risk areas the list addresses include:

  • Malicious skills: Skills designed to harm users or systems.
  • Instruction injection: Skill content that overrides user intent.
  • Excessive permissions: Skills granted more access than needed.
  • Supply chain integrity: Tampered or impersonated skills.
  • Insufficient review: Skills installed without vetting or monitoring.

The Agentic Skills Top 10 complements the OWASP Top 10 for Agentic Applications, which covers broader agent risks such as goal hijack and tool misuse.

Teams can use the list to set policy for which skills are allowed, how they are reviewed, and how their behavior is monitored.

How PointGuard AI Helps

PointGuard AI Agentic Endpoint Security discovers skills and plugins installed in agents and enforces policy on their use, and AI Runtime Guardrails monitor the instructions and actions skills introduce.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.