raigo-owasp-top-10-llmRAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for OpenClaw agents. Covers all 10 OWASP LLM risks: prompt...
Install via ClawdBot CLI:
clawdbot install musharsec/raigo-owasp-top-10-llmGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
Report → https://github.com/PericuloLimited/raigo/issuesPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://raigo.ai/docs/owasp-llmGenerated Jul 17, 2026
A bank deploys an LLM-powered customer service chatbot. The skill prevents prompt injection attacks that could trick the bot into revealing account balances or executing unauthorized transactions, and blocks disclosure of sensitive financial data like account numbers or transaction history.
A healthcare provider uses an LLM to answer patient queries about medical records. The skill ensures no protected health information (PHI) is leaked, and warns against using unverified third-party medical databases that could introduce biased or poisoned data.
An online retailer uses an LLM to generate personalized product recommendations. The skill guards against prompt injection that could manipulate recommendations, and prevents the model from disclosing proprietary pricing or supplier data.
A corporation deploys an LLM for employee queries on internal policies and HR data. The skill blocks attempts to extract sensitive employee PII, prevents overreliance by warning when the model's output may be speculative, and audits any external tool calls to ensure supply chain integrity.
A legal tech startup uses an LLM to summarize and analyze contracts. The skill prevents prompt injection that could alter document interpretations, warns against using untrusted third-party legal databases, and stops disclosure of confidential client information.
Offer the OWASP Top 10 AI skill as a monthly subscription add-on for existing AI agent platforms. Revenue comes from per-agent or per-organization licensing fees, tiered by number of rules and compliance reporting features.
License the skill as a standalone package for enterprises needing OWASP compliance. Includes initial setup, integration support, and annual updates to align with OWASP revisions. Revenue from license sale plus 20% annual maintenance fee.
Provide a free basic version covering core rules for prompt injection and sensitive data disclosure. Charge for advanced features like supply chain auditing, custom rule creation, and compliance dashboards. Revenue from premium tier subscriptions and enterprise audits.
💬 Integration Tip
Import the skill into your OpenClaw agent and it works out-of-the-box with no additional setup. For best results, combine with the RAIGO Agent Firewall for comprehensive coverage.
Scored Jul 17, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...