Skill Wiki v0.1.0
principle @community/principle-owasp-vulnerable-components

Owasp Vulnerable Components

Every third-party dependency must be inventoried (SBOM), continuously scanned for known CVEs, and updated within 30 days for critical/high vulnerabilities.…

Skill
@community
Domain
security
Version
1.0.0
Quality
4.0
Edges
3 out · 1 in
Tokens
153/379/626
$ prime install @community/principle-owasp-vulnerable-components

Projection

Always in _index.xml · the agent never has to ask for this.

OwaspVulnerableComponents [principle] v1.0.0

OWASP Top 10 A06:2021 (formerly Using Components with Known Vulnerabilities) — components such as libraries, frameworks, and runtimes run with the same privileges as the application. If a vulnerable component is exploited, it can facilitate data loss or server takeover.

Every third-party dependency must be inventoried (SBOM), continuously scanned for known CVEs, and updated within 30 days for critical/high vulnerabilities. Applications must never deploy with components that have reached end-of-life without a documented compensating control.

Source

prime-system/examples/frontend-design/primes/compiled/@community/principle-owasp-vulnerable-components/atom.yaml

Compiled at 2026-05-07