CtrlK
BlogDocsLog inGet started
Tessl Logo

agentic-ai-risk-assess

Assess agentic AI applications against the OWASP Top 10 for Agentic Applications 2026. Use when reviewing autonomous AI agents, multi-agent systems, or agentic workflows for security risks including goal hijacking, tool misuse, privilege abuse, and rogue agent behavior.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-structured single-purpose review skill with a clear workflow and concrete risk category breakdown. Its main weakness is that the referenced detail files (plays/agentic-ai-risk-assess.md and templates/finding.md) are not present in the bundle, weakening progressive disclosure.

Suggestions

Add the referenced `plays/agentic-ai-risk-assess.md` and `templates/finding.md` files to the skill bundle so the inline references resolve to real content.

Add an explicit validation/synthesis checkpoint in the workflow (e.g., confirm each of the 10 categories was assessed before synthesizing) to raise workflow clarity.

Inline a brief example finding format or severity rubric so the assessment is actionable without solely deferring to the external play file.

DimensionReasoningScore

Conciseness

The body is lean and efficient with no padding or over-explanation of concepts Claude already knows; every line (architecture mapping, the 10 risk categories, synthesis, output) earns its place.

5 / 5

Actionability

It names concrete sub-issues per risk category and points to specific files (the play and the finding template), but the executable assessment procedure itself is deferred to the external play file rather than given inline, leaving minor gaps.

4 / 5

Workflow Clarity

A clear three-step sequence (Architecture Mapping, Assess Each Risk, Synthesize Findings) is present with most checkpoints implied via the output spec; validation checkpoints are implicit rather than explicit, so it falls short of the feedback-loop anchor 5.

4 / 5

Progressive Disclosure

Structure and one-level-deep signaling are good ('see plays/...md', 'templates/finding.md'), but the referenced bundle files do not exist in the skill directory, so the references are not backed by real files, leaving organization incomplete.

3 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-formed description that clearly states the capability and provides explicit 'Use when' trigger guidance with concrete agentic-AI security keywords. Minor specificity gaps in enumerating the full assessment actions keep it just shy of perfect on specificity and trigger coverage.

DimensionReasoningScore

Specificity

The description names the domain ('agentic AI applications') and lists several concrete risk actions ('goal hijacking, tool misuse, privilege abuse, and rogue agent behavior'), though the primary action is a single umbrella ('Assess...against the OWASP Top 10'), leaving minor coverage gaps versus the comprehensive anchor 5.

4 / 5

Completeness

It clearly answers 'what' ('Assess agentic AI applications against the OWASP Top 10 for Agentic Applications 2026') and explicitly answers 'when' with a 'Use when reviewing...' clause listing concrete triggers.

5 / 5

Trigger Term Quality

It includes natural phrases users would say ('autonomous AI agents, multi-agent systems, agentic workflows, security risks') with good keyword coverage, but a few common variations like 'AI agent security' or 'agent security review' are missing.

4 / 5

Distinctiveness Conflict Risk

It carves a clear niche (agentic AI security against the OWASP Agentic Top 10) with distinct, specific triggers and minimal overlap risk with other skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
OWASP/secure-agent-playbook
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.