Skill Wiki v0.1.0
principle @community/principle-owasp-insecure-design

Owasp Insecure Design

Security requirements must be established before implementation begins, not retrofitted after.…

Skill
@community
Domain
security
Version
1.0.0
Quality
4.0
Edges
3 out · 5 in
Tokens
146/425/665
$ prime install @community/principle-owasp-insecure-design

Projection

Always in _index.xml · the agent never has to ask for this.

OwaspInsecureDesign [principle] v1.0.0

OWASP Top 10 A04:2021 — new category focused on risks from design and architectural flaws. Unlike implementation bugs, insecure design cannot be fixed by a perfect implementation — the threat model was wrong from the start.

Security requirements must be established before implementation begins, not retrofitted after. Use threat modeling (STRIDE or PASTA) in design reviews, define security user stories, and identify trust boundaries explicitly — 'we will add auth later' is an insecure design decision, not a debt item.

Source

prime-system/examples/frontend-design/primes/compiled/@community/principle-owasp-insecure-design/atom.yaml

Compiled at 2026-05-07