Skip to content

docs(claude_skill): CSKILL-060 rationale + OWASP AST/ASI mapping#17

Merged
jhumel-code merged 1 commit into
mainfrom
feat/skill-owasp-cskill060
Jun 8, 2026
Merged

docs(claude_skill): CSKILL-060 rationale + OWASP AST/ASI mapping#17
jhumel-code merged 1 commit into
mainfrom
feat/skill-owasp-cskill060

Conversation

@jhumel-code

Copy link
Copy Markdown
Collaborator

TR-266 + TR-267. Adds the CSKILL-060 (description-vs-tools mismatch) defense, and maps the skill pack to the OWASP Agentic Skills Top 10 (AST03 Over-Privileged, AST04 Insecure Metadata, AST05 Prompt Injection, AST08 Poor Scanning) + ASI04 — IDs only, each consequence argued from mechanism, not from any external incident claim. Positions the pack as the deterministic answer to AST08 (Poor Scanning).

Pairs with the engine + trustabl-rules PRs (same branch). check_rulebook validates against the rules PR, so merge together.

Refs: TR-266, TR-267

Add the CSKILL-060 (description-vs-tools mismatch) rule-by-rule defense, and map
the skill pack to the OWASP Agentic Skills Top 10 (AST03 Over-Privileged, AST04
Insecure Metadata, AST05 Prompt Injection, AST08 Poor Scanning) + ASI04 — IDs
only, with each consequence argued from mechanism, not from any external incident
claim. Position the pack as the deterministic answer to AST08. Regenerate
POLICY_INDEX.md.

Refs: TR-266, TR-267
@jhumel-code jhumel-code merged commit d9c0ec2 into main Jun 8, 2026
2 checks passed
@jhumel-code jhumel-code deleted the feat/skill-owasp-cskill060 branch June 8, 2026 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant