Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
common-owasp - Skill - OpenSmartRoute
Skillv1.0.0
common-owasp
OWASP Top 10 audit checklist for Web Applications (2021) and APIs (2023). Load during any security review, PR review, or codebase audit touching web, mobile backend, or API code. (triggers: security r
Imported from wildbitca/ai-resources (skills/common-owasp/SKILL.md). Install upstream with npx skills add wildbitca/ai-resources --skill common-owasp. Copyright stays with the author.
OWASP Top 10 Security Checklist
Priority: P0 (CRITICAL)
Implementation Guidelines
Check A01/API1 first: IDOR is the #1 finding in real codebases — any findById(userInput) without an owner/tenant filter is an immediate P0.
Mark each item: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.
P0 finding caps Security score at 40/100 — do not skip any item.
Apply framework-specific security skills alongside this checklist.
Install common-owasp and it becomes one more candidate the router can pick - when it fits.
A listing is a routing target with a manifest: what it does, which domains it covers, what it costs and who publishes it. Once installed it sits beside your own models and tools, is scored like any other candidate for each request, and shows up in the trace when it wins. Ratings come from workspaces that installed it, one per account.
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - a plan picks it for its slot
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.
wildbitca-ai-resources-common-owasp.ocm.jsonjson
{
"ocm": "1",
"id": "wildbitca-ai-resources-common-owasp",
"kind": "skill",
"name": "common-owasp",
"description": "OWASP Top 10 audit checklist for Web Applications (2021) and APIs (2023). Load during any security review, PR review, or codebase audit touching web, mobile backend, or API code. (triggers: security review, OWASP, broken access control, IDOR, BOLA, injection, broken auth, API review, authorization, access control)",
"publisher": "wildbitca",
"version": "1.0.0",
"capabilities": {
"domains": [
"coding"
],
"tags": [
"skill-md",
"github"
],
"languages": [
"en"
]
},
"quality_prior": 0.6,
"examples": [
"OWASP Top 10 audit checklist for Web Applications (2021) and APIs (2023). Load during any security review, PR review, or codebase audit touching web, mobile backend, or API code. (triggers: security review, OWASP, broken access control, IDOR, BOLA, injection, broken auth, API review, authorization, access control)"
],
"primary": false,
"metadata": {
"source": {
"provider": "github",
"repository": "https://github.com/wildbitca/ai-resources",
"path": "skills/common-owasp/SKILL.md",
"ref": "84c6e28aecd33b8851f7502530b249a127af534b",
"url": "https://github.com/wildbitca/ai-resources/blob/84c6e28aecd33b8851f7502530b249a127af534b/skills/common-owasp/SKILL.md",
"key": "wildbitca/ai-resources/skills/common-owasp/SKILL.md"
}
},
"instructions": "# OWASP Top 10 Security Checklist\n\n## **Priority: P0 (CRITICAL)**\n\n## Implementation Guidelines\n\n- **Check A01/API1 first**: IDOR is the #1 finding in real codebases — any `findById(userInput)` without an owner/tenant filter is an immediate P0.\n- **Mark each item**: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.\n- **P0 finding caps Security score at 40/100** — do not skip any item.\n- Apply framework-specific security skills alongside this checklist.\n- See [references/owasp-web.md](references/owasp-web.md) and [references/owasp-api.md](references/owasp-api.md) for full detection signal",
"cost": {
"context_tokens": 938
}
}
Fetch it by URL: GET /api/v1/registry/wildbitca-ai-resources-common-owasp/manifest?version=1.0.0
Reviews
Star ratings from people who tried it. One review per account; edit yours any time.
No reviews yet. Install it, try it, and be the first to rate it.