Analysis · curated 25 Aug 2026
OWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first
First reported adversa.ai
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
The OWASP Agentic Skills Top 10 names a distinct attack surface — install-time prose that executes and evades both package-security and prompt-injection defenses — that defenders of agent platforms must inventory and scope before it scales as ClawHavoc already did.
Adversa AI explains the OWASP Agentic Skills Top 10 (AST01-AST10), a version 1.0 framework published August 17, 2026 covering the risks of agent 'skills' — prose SKILL.md files with frontmatter and bundled scripts that agents discover, load, and execute autonomously. The piece cites real evidence including three-line markdown that exfiltrated SSH keys and the ClawHavoc campaign that pushed 1,184 malicious skills through twelve accounts on the ClawHub registry, and recommends fixing in order of inventory, isolation/credential scoping, pinning, then detection.