Skip to main content

In this article

owasp-cicd

owasp-cicd
FieldValue
Kindskill
Source.github/skills/security/owasp-cicd
InvocationLoaded on demand by referencing agents
InteractiveNo

What it does​

OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.

When to use it​

Load this reference in an agent-led security review of build, test, and deployment pipelines. It is useful when untrusted contributions, workflow identities, third-party dependencies, or release artifacts cross trust boundaries. Choose supply-chain-security for the broader Scorecard, provenance, SBOM, and supply-chain planning vocabulary rather than only pipeline risk categories.

Example usage​

Ask a reviewing agent to load owasp-cicd and inspect a sanitized workflow that builds pull requests and publishes releases. Supply the workflow YAML, permission settings, and artifact-promotion description; request read-only findings.

The agent should use the vulnerability index to investigate applicable concerns such as pipeline execution, credential hygiene, and artifact integrity. A useful result names the affected workflow step, supporting evidence, risk category, and proposed correction, while separating unavailable repository settings from proven defects. No pipeline run, credential disclosure, permission change, or release publication is needed to illustrate this review.