OWASP Flags Top AI Skill Risks in New Security Blueprint

Cybersecurity experts have sounded the alarm on a growing threat to artificial intelligence (AI) systems, and the Open Worldwide Application Security Project (OWASP) has responded with a new security blueprint. In a recent high-profile attack, cyber attackers exploited vulnerabilities in AI skills – essentially scripts that add features and capabilities to these platforms – to compromise users’ machines and steal sensitive information.

The incident highlights the risks associated with agentic skills, which are natural-language or coded recipes for integrating AI into various applications. While these skills make AI agents more capable, they also introduce significant security concerns, including untrusted input and malicious code. The OWASP list identifies the top 10 security issues related to agentic skills, with “Malicious Skills” holding the current number one spot.

One of the key takeaways from this new security blueprint is that legitimate skills are not inherently secure. Even if they’re written in a natural language or using code, they can be subject to abuse and exploitation by attackers. The OWASP list highlights the importance of addressing these risks proactively, particularly in supply chains where agentic skills are often hosted on external resources like GitHub.

The top 10 security issues identified by OWASP include two critical risks: “Malicious Skills” and “Supply Chain Compromise.” The latter refers to the potential for attackers to manipulate repository systems and compromise a large number of agents within hours, as seen in an experiment conducted by agentic-security startup Air. This attack resulted in over 26,000 compromised agents.

The OWASP list also identifies several high-severity risks associated with skills, including “Untrusted Input” and “Lack of Security Models.” To mitigate these risks, OWASP has introduced a new standardized YAML format for skills files that can help automated analysis determine which skills are legitimate. The intent is to provide organizations with a way to identify potential security threats before they become major incidents.

Security practitioners like Omar Turner, who supports the effort and manages cloud and AI security projects at Microsoft, emphasize the importance of reviewing and addressing risks associated with agentic skills. “Without the knowledge of what risks could exist with skills, you’re kind of operating blind,” he notes. Niv Hoffman, co-lead of the OWASP project and CTO of Air, adds that while skills can have risks, they shouldn’t be forbidden but rather used in a secure-by-default environment.

The OWASP Agentic Skills Top 10 list serves as a critical resource for organizations looking to integrate AI into their operations securely. By understanding these risks and taking proactive steps to address them, businesses can minimize the potential for security breaches and protect their users’ sensitive information.


Source: Dark Reading — 2026-08-21