OWASP / Agentic Skills Top 10

OWASP Agentic Skills Top 10, mapped to BitEvo authority and evidence gates

OWASP Agentic Skills Top 10 documents ten security risks for agentic skills. This BitEvo mapping is a scoping aid: it shows which of our seven gates can test the action or evidence consequence of each risk in one agreed workflow. It does not claim to cover the whole OWASP risk or certify a skill.

AST01–AST10 · current public-review v1 names

Risk → BitEvo gates → evidence → scope boundary

AST01 · OWASP risk

Malicious Skills

BitEvo gates: Authority Budget · Evidence Before Effect

Evidence we would scope

Exact skill identity and version, the consequential action it can trigger, and the rule that allowed or refused that action.

Scope boundary

We test bounded action consequences and evidence gates. Malware reverse engineering is out of scope.

AST02 · OWASP risk

Supply Chain Compromise

BitEvo gates: Freshness · Evidence Before Effect

Evidence we would scope

The source and exact artifact version or hash available at decision time, plus the re-approval or blocking rule when that artifact changes.

Scope boundary

We test reliance on the installed artifact in the agreed workflow. Registry or platform compromise analysis is out of scope.

AST03 · OWASP risk

Over-Privileged Skills

BitEvo gates: Authority Budget · Object binding

Evidence we would scope

The actions and objects the skill is supposed to reach, compared with the permissions and effects it can actually reach.

Scope boundary

Core authority scope: whether the granted capability exceeds the written action and object boundary.

AST04 · OWASP risk

Insecure Metadata

BitEvo gates: Authority owner · Evidence Before Effect

Evidence we would scope

Publisher or owner metadata and declared permissions used to authorize the skill, compared with the action surface observed in the workflow.

Scope boundary

We test whether metadata is trusted beyond its evidence. We do not operate or certify a signing ecosystem.

AST05 · OWASP risk

Untrusted External Instructions

BitEvo gates: Freshness · Evidence Before Effect

Evidence we would scope

Origin, version or retrieval time for external instructions, and whether changed content can authorize an action without renewed validation.

Scope boundary

Mutable external instructions are treated as a decision-time evidence dependency; content-security research outside the workflow is out of scope.

AST06 · OWASP risk

Weak Isolation

BitEvo gates: Authority Budget · Recovery

Evidence we would scope

The allowed filesystem, network or shell actions and the constrained state reached when an attempted action crosses that boundary.

Scope boundary

We validate the agreed control boundary. Sandbox-escape exploit development is out of scope.

AST07 · OWASP risk

Update Drift

BitEvo gates: Freshness · Evidence Before Effect

Evidence we would scope

The skill version or hash loaded for the decision and the rule that blocks or re-approves execution after version drift.

Scope boundary

We test freshness and change handling for the one skill or workflow in scope.

AST08 · OWASP risk

Poor Scanning

BitEvo gates: Evidence Before Effect · Authority Budget

Evidence we would scope

The scanner or review result relied on before effect and which consequential actions remain reachable after that result.

Scope boundary

We test a scanner result as an evidence gate for the agreed workflow; this is not a universal scanner benchmark.

AST09 · OWASP risk

No Governance

BitEvo gates: Authority owner · Recovery

Evidence we would scope

Who owns inventory, approval and revocation for the skill, and the constrained state reached after authority is revoked or becomes uncertain.

Scope boundary

We test the governance boundary for one agreed workflow or skill, not enterprise-wide governance certification.

AST10 · OWASP risk

Cross-Platform Reuse

BitEvo gates: Object binding · Authority Budget · Freshness

Evidence we would scope

The source and target platform permission semantics, the target object actually selected, and any capability drift introduced by the port.

Scope boundary

We test one agreed portability case; we do not claim coverage of every agent platform.

Mapping boundary

BitEvo mapping for scoping only.

Not an OWASP certification or endorsement. The official AST10 project defines the risks; BitEvo is only mapping them to evidence questions for a bounded workflow.