Research: agent-owasp-compliance
Cached research evidence for agent-owasp-compliance (not authority).
Purpose
Section titled “Purpose”awesome-copilot skill for OWASP compliance patterns specific to AI/agentic systems (prompt injection, insecure output, supply chain for agents, etc).
Harness Coverage
Section titled “Harness Coverage”Target agents: antigravity, claude-code, codex, crush, cursor, gemini-cli, github-copilot, grok, opencode.
Trust And Risks
Section titled “Trust And Risks”trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; GitHub curated collection; valuable checklist but static guidance; review applicability to current threat model.
Install Prerequisites
Section titled “Install Prerequisites”Install: subset of github/awesome-copilot bundle; status=inspect-then-install; selector=named; policy=Inspect source, hooks, scripts, credentials, and dedupe before install.
Upstream Maintainer
Section titled “Upstream Maintainer”github/awesome-copilot (GitHub curated)
Comparable Alternatives
Section titled “Comparable Alternatives”OWASP LLM Top 10 skills or security review skills; agent-governance, mcp-security-audit.
> Evidence synthesized from public web sources (GitHub repos, official docs, skill registries); confidence reflects source reputation and public signals only. Not an endorsement.
