
OWASP-WSTG-Rag
OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.


A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Twitter vulnerable snippets

OWASP Smart Contract Security (SCS) Project

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Application Security Verification Standard

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…