In this article
owasp-cicd
| Field | Value |
|---|---|
| Kind | skill |
| Source | .github/skills/security/owasp-cicd |
| Invocation | Loaded on demand by referencing agents |
| Interactive | No |
What it does
OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.
When to use it
Load this reference in an agent-led security review of build, test, and deployment
pipelines. It is useful when untrusted contributions, workflow identities,
third-party dependencies, or release artifacts cross trust boundaries. Choose
supply-chain-security for the broader Scorecard, provenance, SBOM, and supply-chain
planning vocabulary rather than only pipeline risk categories.
Example usage
Ask a reviewing agent to load owasp-cicd and inspect a sanitized workflow that
builds pull requests and publishes releases. Supply the workflow YAML, permission
settings, and artifact-promotion description; request read-only findings.
The agent should use the vulnerability index to investigate applicable concerns such as pipeline execution, credential hygiene, and artifact integrity. A useful result names the affected workflow step, supporting evidence, risk category, and proposed correction, while separating unavailable repository settings from proven defects. No pipeline run, credential disclosure, permission change, or release publication is needed to illustrate this review.