LLM risk assess — audit LLM apps against the OWASP Top 10 for LLM Applications 2025 (short listing)
⚠️ Dual-use — authorized use only. Short listing — license not verifiable; comprehensive LLM security assessment: threat modeling, injection probes, all 10 OWASP LLM 2025 risks, red team testing
- What
- ⚠️ Dual-use — authorized use only. Short listing — license not verifiable; comprehensive LLM security assessment: threat modeling, injection probes, all 10 OWASP LLM 2025 risks, red team testing
- Cost
- Free
- Needs
- an LLM-integrated application, RAG pipeline, or AI agent that you own or are explicitly authorized to security-test
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Selected by Skill Harbor — ⚠️ Dual-use — AUTHORIZED USE ONLY: this is a defensive security playbook, but it ships real attack techniques (prompt injection probes, jailbreak testing, defense-bypass and evasion testing, system-prompt extraction) — use it only on systems you own or are explicitly authorized to test. Short listing (the discovery manifest records NOASSERTION — the manifest makes faith, so no content is reproduced beyond this summary): @owasp's llm-risk-assess play: a structured security assessment of LLM-integrated applications against the OWASP Top 10 for LLM Applications 2025 — architecture and threat modeling (data flows, trust boundaries, RAG and tool integration mapping), automated security testing, coverage of all ten risk categories (prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector/embedding weaknesses, misinformation, unbounded consumption) with real-world attack scenarios, red team testing, and a remediation roadmap with code examples. Honest caveats: license terms not verifiable — short listing with a link only; the allowed-tools list includes Bash and WebFetch, so the agent can run real probes — keep it sandboxed and scoped to authorized targets. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: an LLM-integrated application, RAG pipeline, or AI agent that you own or are explicitly authorized to security-test Install "LLM risk assess — audit LLM apps against the OWASP Top 10 for LLM Applications 2025 (short listing)" for me. It gives my agent @owasp's llm-risk-assess play: map the architecture and threat model (LLM provider, data flows, RAG components, trust boundaries), run automated security testing (injection probes, secret scans, vector DB checks), assess all 10 OWASP LLM 2025 risks with attack scenarios, run red team tests, and produce a risk matrix with findings, proof-of-concept examples, and a remediation roadmap. IMPORTANT: dual-use — authorized use only; run probes only against systems I own or am authorized to test. License terms were not verifiable (the discovery manifest records NOASSERTION) — fetch from the link only, reproduce nothing beyond the link, and read the license terms yourself before reuse. Repository: https://github.com/owasp/secure-agent-playbook/blob/main/plugins/ai-security-skills/skills/llm-risk-assess/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "llm-risk-assess". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm which application I am authorized to assess, read the license terms before reuse). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.