Community & Contribution Guide
Community & Contribution Guide
The OWASP Agentic Skills Top 10 project thrives through community participation. This guide explains how you can contribute to improving AI agent skill security.
Ways to Contribute
1. Security Research & Analysis
What We Need:
- Vulnerability analyses of published skills
- Threat modeling and attack scenarios
- Security testing methodologies
- Incident documentation
How to Contribute:
1. Research a security aspect of AI agent skills
2. Document your findings in a GitHub issue
3. Create a pull request with your analysis
4. Participate in peer review
# Example Research Contribution
- Topic: "Zero-Day Vulnerability in SKILL.md Parsing"
- Format: GitHub discussion or pull request
- Include: Technical details, test cases, remediation
Recognition:
- Author credit in documentation
- Featured researcher profile
- Speaking opportunities at OWASP events
2. Documentation Improvements
What We Need:
- Clearer explanations of risks
- Additional code examples
- Platform-specific guides
- Translation to other languages
How to Contribute:
# Fork the repository
git clone https://github.com/YOUR_USERNAME/www-project-agentic-skills-top-10.git
# Create a branch for your improvements
git checkout -b improve/documentation
# Make improvements
# - Update existing docs
# - Add examples
# - Fix typos
# - Clarify explanations
# Commit and push
git commit -m "Improve documentation for [topic]"
git push origin improve/documentation
# Create pull request
Documentation Standards:
- Follow existing markdown format
- Include code examples where applicable
- Add cross-references to related risks
- Update table of contents if adding sections
3. Tool Development
What We Need:
- Security scanning tools
- Automated assessment frameworks
- CLI utilities
- Browser extensions
Featured Tools:
Skill scanner rule contributions
# Pick an active scanner project used by this guide
git clone https://github.com/NVIDIA/SkillSpector
cd SkillSpector
# Add new detection rules
vim src/skillspector/nodes/analyzers/static_patterns_prompt_injection.py
# Add test cases
vim tests/nodes/analyzers/test_static_patterns.py
# Submit pull request
Skill Validator
// Contribute to web-based validator
// Location: /tools/skill-validator
// Technologies: React, TypeScript, TailwindCSS
// Add new validation rule
export const validateSkillPermissions = (skill) => {
// Implementation
}
// Add unit test
describe('validateSkillPermissions', () => {
it('should detect over-privileged skills', () => {
// Test case
})
})
4. Training & Educational Content
What We Need:
- Tutorial videos
- Workshop materials
- Certification courses
- Interactive learning modules
Create Video Tutorials:
Topics needed:
1. "Getting Started with Secure Skill Development"
2. "AST10 Risk Identification Walkthrough"
3. "Setting Up CI/CD Security Scanning"
4. "Platform Comparison: Choosing Your Ecosystem"
Format:
- 5-15 minute videos
- Screen recorded with narration
- Subtitles for accessibility
- Code examples included
Workshop Materials:
- Hands-on labs with sample skills
- Security audit guided exercises
- Remediation workshops
- Certification exam prep
5. Community Support
What We Need:
- Answer questions in discussions
- Help with security reviews
- Mentor new contributors
- Facilitate community events
Support Roles:
- Discussion Moderator: Help answer questions, direct to resources
- Code Reviewer: Review pull requests, suggest improvements
- Event Organizer: Organize local meetups or webinars
- Ambassador: Promote AST10 in your network
Contribution Process
Step-by-Step Guide
1. Identify Contribution
- Check GitHub issues for open items
- Propose new research in discussions
- Review roadmap for planned work
2. Set Up Development Environment
# Clone repository
git clone https://github.com/OWASP/www-project-agentic-skills-top-10.git
cd www-project-agentic-skills-top-10
# Create feature branch
git checkout -b feature/your-contribution-name
# Set up locally
# For documentation: No setup needed
# For tools: See individual tool documentation
3. Make Your Contribution
# Make improvements to files
# Test thoroughly
# Add documentation
# Update references
4. Submit for Review
# Commit changes
git add .
git commit -m "Description of contribution
- Details of what was added/changed
- Links to related issues
- Any testing performed"
# Push to your fork
git push origin feature/your-contribution-name
# Create pull request on GitHub
# - Link related issues
# - Describe changes clearly
# - Tag reviewers if known
5. Participate in Review
- Respond to reviewer feedback
- Make requested changes
- Answer clarifying questions
- Update based on suggestions
6. Merge & Recognition
- PR gets approved and merged
- You're added to contributors list
- Your contribution appears in release notes
- Recognition in community announcements
Code of Conduct
All contributors agree to:
- Be Respectful: Treat all community members with respect
- Constructive Criticism: Provide feedback that helps improve
- Inclusivity: Welcome contributors from all backgrounds
- Security Focus: Prioritize security and user safety
- Transparency: Be open about limitations and trade-offs
Contribution Areas
High Priority (Looking for Contributors Now)
- Spanish translation of documentation
- Python skill scanner implementation
- Interactive platform comparison tool
- Incident response playbooks
- Video tutorials (Basic to Advanced)
- Hands-on security labs
- API SDK for additional languages (Go, Rust)
Medium Priority
- Additional case studies (post-2026)
- Platform-specific deep dives
- Custom rule development guide
- Skill audit checklist tools
- Security training certification
Community-Driven
- Research on emerging threats
- New risk discovery and analysis
- Tool integrations
- Community-submitted best practices
Recognition & Rewards
Contributors List
All contributors are recognized in:
- GitHub Contributors page
- Project documentation
- Monthly community highlights
- Annual OWASP reports
Speaking Opportunities
- Present at OWASP AppSec conferences
- Lead workshops and training sessions
- Guest appearances on podcast
- Author guest articles
Certification Pathway
Contributing significantly can lead to:
- OWASP AST10 Security Analyst Certification
- Featured Expert status
- Speaking engagement opportunities
- Career advancement in security
Community Channels
GitHub
- Issues: Report bugs, suggest features
- Discussions: Ask questions, share ideas
- Pull Requests: Submit contributions
- Releases: Follow project updates
Contact
- Email: [email protected]/ast10
- Twitter: @OWASP
- Forum: OWASP Project Forum
Contributors Hall of Fame
Active Contributors (2026)
Research Contributors
- Thanks to Snyk researchers for ToxicSkills data
- Check Point Research for ClawHavoc analysis
- Antiy CERT for threat intelligence
Documentation Contributors
- [Your name here - get started today!]
Tool Developers
- Community developers of AST10-Scanner
- Security researchers building detection tools
Getting Help
For Questions
1. Check existing GitHub discussions
2. Ask in GitHub Discussions tab
3. Contact project leads
4. Post in community forums
For Technical Issues
1. Check documentation/troubleshooting
2. Search closed GitHub issues
3. Open new issue with details
4. Contact maintainers if needed
For Security Issues
1. DO NOT post publicly
2. Email: [email protected]
3. Include details but no sensitive info
4. Follow responsible disclosure
Start Contributing Today!
New to contributing?
- Look at “good first issue” label on GitHub
- Start with documentation improvements
- Submit your first pull request
- Join the community!
Ready to dive deeper?
- Review open research topics
- Propose new security analysis
- Develop security tools
- Become a community mentor
Questions?
- Check CONTRIBUTING.md for detailed guidelines
- Open a GitHub issue
- Email: [email protected]
Welcome to the OWASP AST10 community! 🛡️
Last updated: March 2026
Example
Put whatever you like here: news, screenshots, features, supporters, or remove this file and don’t use tabs at all.
Leadership & Founding Members
Project Leadership
Current Leaders
Ken Huang
Hammad Atta
Fabio Cerullo
Aonan Guan
Bhavya Gupta
Niv Hoffman
Iftach Orr
Akram Sheriff
AIVSS Distinguished Review Board
The OWASP AIVSS project’s Distinguished Review Board comprises world-renowned cybersecurity leaders, former government officials, and industry pioneers who provide strategic guidance and expert oversight for the AI Vulnerability Scoring System framework. We thank them for their guidance, several of whom have also supported this project’s work.
Rob Joyce
Advisor to PwC and OpenAI, Former Special Assistant to the President and Cybersecurity Coordinator
Jason Clinton
Deputy CISO, Anthropic
Amy R. Steagall
Chief Information Security Officer, Stanford University
Martin Stanley
AI Risk Management Framework Lead, NIST
Apostol Vassilev
Research Supervisor, NIST
Andrew Coyne
CISO, Banner Health, Former CISO, Mayo Clinic
Kevin Rocque
Managing Director/Executive Vice President, Global Technology Risk Officer, TD Bank
Jeff Williams
Former Global OWASP Chair, Founder and CTO, Contrast Security
Michael Tran Duff
University Chief Information Security and Data Privacy Officer, Harvard University
Emil Bender Lassen
Standards Lead, AIUC-1
Agentic Skills Top 10 Founding Members
Founding members of the OWASP Agentic Skills Top 10 project itself — project leads, co-leads, and additional contributors — listed alphabetically. Several also contribute to the sibling OWASP AIVSS project listed above.
Ken Huang
Project Lead, Agentic Skills Top 10
Hammad Atta
Co-Lead, Agentic Skills Top 10
Manish Bhatt
Security Researcher, AWS
Fabio Cerullo
Co-Lead, Agentic Skills Top 10
David Girard
Senior Director, AI Security & AI Alliances, Trend Micro
Aonan Guan
Co-Lead, Agentic Skills Top 10
Bhavya Gupta
Co-Lead, Agentic Skills Top 10
Pamela Gupta
Founder & CEO, OutSecure / Trusted AI
Idan Habler
Staff AI/ML Security Researcher, Intuit
Niv Hoffman
CTO, Air Security
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Sushmitha Janapareddy
Director - Security Integrations, American Express
Edward Lee
Vice President, Lead AI Security, JP Morgan
KJ Lian
Senior Manager, Data & AI (Public Sector), AWS
Vineeth Sai Narajala
Application Security, AWS
Iftach Orr
Co-Lead, Agentic Skills Top 10
Kanna Sekar
Cyber Security, Google
Akram Sheriff
Co-Lead, Agentic Skills Top 10
Dennis Xu
Research VP, AI, Gartner
OWASP AIVSS Founding Members
The OWASP AIVSS (Agentic AI Vulnerability Scoring System) project is a sibling OWASP initiative focused on scoring the severity of agentic AI vulnerabilities. Its founding members are recognized here as OWASP founding members in the agentic AI security space; many of them have also contributed directly to the Agentic Skills Top 10 project’s research and review process.
Sunil Agrawal
Chief Information Security Officer, Glean
David Ames
Partner, PwC
Michael Bargury
Founder and CTO, Zenity
Joshua Beck
Application Security Architect, SAS
Manish Bhatt
Security Researcher, Amazon Kuiper Security
Mark Breitenbach
Security Engineer, Dropbox
Anat Bremler-Barr
Professor of Computer Science, Tel Aviv University
Siah Burke
HIPAA Security Officer, Siah.ai
David Campbell
AI Security, Scale AI
Ying-Jung Chen
AI safety researcher, PhD, Georgia Institute of Technology
Anton Chuvakin
Security Solution Strategy, Google
Jason Clinton
CISO, Anthorphic
Adam Dawson
Staff AI Security Researcher, Dreadnode
Leon Derczynski
Principal Research Scientist, NVIDIA
Walker Lee Dimon
AI Security Researcher, MITRE
Marissa Dotter
AI Security Researcher, MITRE
Dan Goldberg
ISO Market Lead, Omnicom
David Haber
CEO, Lakera
Idan Habler
Staff AI/ML Security Researcher, Intuit
Jason Haddix
Founder, Arcanum Information Security
Keith Hoodlet
Director of AI/ML & AppSec, Trail of Bits
Ken Huang
AIVSS Project Lead, OWASP
Chris Hughes
CEO, Aquia
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Krystal Jackson
Researcher, Center for Long-Term Cybersecurity, UC Berkeley
Sushmitha Janapareddy
Director - Security Integrations, American Express
Rob Joyce
Former Cybersecurity Director of NSA, Advisor to PwC, PwC
Diana Kelley
CISO, Noma Security
Prashant Kulkarni
Lead AI Security Research Engineer, Google Cloud
Mahesh Lambe
Founder, MIT, Unify Dynamics
Edward Lee
Vice President, Lead AI Security, JP Morgan
Nate Lee
CEO, Cloudsec.ai
Vishwas Manral
CEO, Precize.ai
Daniela Muhaj
Executive-in-Residence for Research & Development, AI 2030
Vineeth Sai Narajala
Application Security, AWS
Om Narayan
AI Security Researcher, AWS
Varun Pant
Engineering and Product Leader, AI applications at the Automated Reasoning Group, AWS
Advait Patel
Senior Site Reliability Engineer (DevSecOps + Cloud + AIOps), Broadcom, IEEE
Alex Polyakov
CEO, adversa.ai
Ramesh Raskar
Professor & Director, MIT Media Lab
Ron F. Del Rosario
VP-Head of AI Security, SAP
Tal Shapira
Co-Founder & CTO, Reco AI
Akram Sheriff
Senior AI/ML Software Engineering Leader, Cisco
Samantha Siau
Security and Compliance, Anthropic
Kevin Simmonds
Partner on AI Offensive Security, PWC
Martin Stanley
NIST AI RMF Lead, Independent
Omar A. Turner
General Manager of Security, Microsoft
Apostol Vassilev
AI Research Team Supervisor, NIST
Matthew Versaggi
AI Fellow, White House Presidential Innovation Fellow
David Webb
Agency Cybersecurity Officer, Cybersecurity and Infrastructure Security Agency
Dennis Xu
Research VP, AI, Gartner
Xiaochen Zhang
Executive Director and Chief Responsible AI Officer, AI 2030
Recognition
We extend our gratitude to all founding members who have contributed to establishing this crucial framework for AI security assessment. Their vision and dedication have been instrumental in shaping the Agentic Skills Top 10 project.
Get Involved
Interested in contributing to the Agentic Skills Top 10 project? We welcome new contributors and leaders. Please see our Contribution Guidelines for more information on how to get involved.