Definition · AI agents
OWASP Agentic Skills Top 10
The OWASP Agentic Skills Top 10, or AST10, is an early-stage OWASP project that lists the ten most critical security risks in agent skills: reusable packages of instructions, scripts and metadata that an AI agent loads to carry out a task. Its entries run from AST01 Malicious Skills to AST10 Cross-Platform Reuse.
Last reviewed
Key points
- The list centres on the skill, the package an agent loads and follows. It leaves MCP servers to OWASP's MCP Top 10 and maps each entry to OWASP's LLM and Agentic (ASI) lists.
- The GitHub repository was created in March 2026, two months after the attacks on the ClawHub skill registry that open the project's incident timeline. It is still an OWASP Incubator project, OWASP's label for work still being designed.
- The list has already changed. On 24 June 2026 OWASP merged a change that folded AST05 Unsafe Deserialization into AST04 and made AST05 Untrusted External Instructions.
- The project page rates each risk Critical, High or Medium. The V1 whitepaper deliberately rates none of them yet.
What is on the list
The ten entries, grouped as the V1 whitepaper groups them.
| Area | Entry |
|---|---|
| Where the skill comes from | AST01 Malicious Skills |
| AST02 Supply Chain Compromise | |
| AST04 Insecure Metadata | |
| What it can reach when it runs | AST03 Over-Privileged Skills |
| AST05 Untrusted External Instructions | |
| AST06 Weak Isolation | |
| How it is kept up to date and watched | AST07 Update Drift |
| AST08 Poor Scanning | |
| AST09 No Governance | |
| What survives a move between platforms | AST10 Cross-Platform Reuse |
AST01 is the attack this site calls agent skill poisoning. AST05 covers a skill that tells the agent to read a remote page, which can change after the skill was reviewed.
What the list covers
The list applies to the skill: an instruction file, such as a SKILL.md, plus its scripts and metadata. The project page covers the skill formats of OpenClaw, Claude Code, Cursor/Codex and VS Code. Servers speaking the Model Context Protocol go to OWASP’s MCP Top 10.
The list overlaps two other OWASP lists rather than replacing them. The whitepaper maps each entry to IDs in the OWASP LLM Top 10 and the OWASP Top 10 for Agentic Applications, whose IDs run ASI01 to ASI10. It warns readers not to mix up AST and ASI numbers. Note too that “AST10” names both the whole list and its tenth entry.
Why it matters
The project says it exists to give builders, enterprises, marketplaces and reviewers a shared vocabulary for skills. Its incident timeline begins with the ClawHavoc campaign, which flooded the ClawHub registry with malicious skills in late January 2026.
Using the list
Cite the date with the number. The list is young and still moving. On 24 June 2026 OWASP merged a change that folded AST05 Unsafe Deserialization into AST04 Insecure Metadata and gave AST05 to Untrusted External Instructions. In OWASP’s words, referenced content can change after review, “so the skill that was audited is never the skill that actually runs.” SecureFlag’s overview of the list, posted on 23 June, shows the old AST05.
File a finding once. The whitepaper gives a decision tree for picking one primary entry. A skill that was malicious when published is AST01. A scanner that missed it is recorded as a contributing failure, not as a second finding.
Check the release status. As of 27 September 2026 the project is an OWASP Incubator project, the label OWASP gives work that is still being designed and proven. A whitepaper marked V1 was posted in August 2026. The project page is less settled. It gives the version as 1.0 (2026 Edition) in one place and 0.0.0 in its sidebar. It still calls the project a new proposal and asks for comments on the v1 draft. It dates the v1.0 release to the third quarter of 2026 in one table and the fourth in another.
Where definitions disagree
The two official texts disagree on severity. The project page rates AST01 and AST02 Critical, AST03 to AST06 High, and AST07 to AST10 Medium. The V1 whitepaper says it deliberately rates none of them until AIVSS, OWASP’s AI Vulnerability Scoring System, reaches v1, which it expects by the end of 2026. Until the two agree, treat the page’s ratings as the project’s working view and not as scores.
Questions and answers
What is AST10?
AST10 is the short name of the OWASP Agentic Skills Top 10, a list of the ten most critical security risks in agent skills. These are the packages of instructions and scripts that AI agents such as Claude Code and OpenClaw load to carry out a task. Its tenth entry, Cross-Platform Reuse, is also numbered AST10.
What are the ten risks in the OWASP Agentic Skills Top 10?
As of September 2026 they are AST01 Malicious Skills, AST02 Supply Chain Compromise, AST03 Over-Privileged Skills, AST04 Insecure Metadata, AST05 Untrusted External Instructions, AST06 Weak Isolation, AST07 Update Drift, AST08 Poor Scanning, AST09 No Governance and AST10 Cross-Platform Reuse.
How is AST10 different from the OWASP Agentic Top 10 (ASI)?
The ASI list, IDs ASI01 to ASI10, comes from OWASP's Agentic Security Initiative. AST10 applies specifically to skills, the packages an agent loads, and maps each of its entries to ASI and LLM Top 10 IDs. Its whitepaper warns readers not to confuse AST numbers with ASI numbers.
Why do older articles list AST05 as Unsafe Deserialization?
That was AST05 until 24 June 2026, when OWASP merged a change that folded it into AST04 Insecure Metadata and gave the slot to Untrusted External Instructions. Articles written before then may show the old list.
Sources
- OWASP Agentic Skills Top 10, project pageOWASP
- OWASP/www-project-agentic-skills-top-10, GitHub repository metadataGitHub
- OWASP Project Handbook, LifecycleOWASP
- OWASP Agentic Skills Top 10, Whitepaper (V1)OWASP, Aug 2026
- OWASP/www-project-agentic-skills-top-10, pull requestOWASP, 24 Jun 2026
- OWASP Agentic Skills Top 10, AST05 Untrusted External InstructionsOWASP
- Inside the OWASP Agentic Skills Top 10SecureFlag, 23 Jun 2026