OWASP Agentic Top 10 [Part 1] | Episode 70
In this episode of BHIS Presents: AI Security Ops, the team breaks down the first five risks in the OWASP Agentic Skills Top 10 (Part 1).
Agentic skills can give AI systems reusable instructions, workflows, and capabilities — but they also introduce a new attack surface. A skill may look like a simple markdown file, yet the agent following those instructions could have access to your filesystem, credentials, network, shell, or other sensitive resources.
We dig into:
- AST01: Malicious Skills
- AST02: Supply Chain Compromise
- AST03: Overprivileged Skills
- AST04: Insecure Metadata
- AST05: Untrusted External Instructions
- Why skills should be treated more like software than configuration
- How excessive permissions increase an agent’s blast radius
- Why external content creates indirect prompt injection risks
- How isolation, least privilege, and trusted sources can reduce risk
The takeaway: “just markdown” isn’t necessarily harmless when an AI agent can act on what it reads.
This is Part 1 of our look at the OWASP Agentic Skills Top 10, covering AST01 through AST05.
—
Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/
Check out Antisyphon Training:
https://www.antisyphontraining.com/
Click here to watch this episode on YouTube.
Brought to you by:
Agentic skills can give AI systems reusable instructions, workflows, and capabilities — but they also introduce a new attack surface. A skill may look like a simple markdown file, yet the agent following those instructions could have access to your filesystem, credentials, network, shell, or other sensitive resources.
We dig into:
- AST01: Malicious Skills
- AST02: Supply Chain Compromise
- AST03: Overprivileged Skills
- AST04: Insecure Metadata
- AST05: Untrusted External Instructions
- Why skills should be treated more like software than configuration
- How excessive permissions increase an agent’s blast radius
- Why external content creates indirect prompt injection risks
- How isolation, least privilege, and trusted sources can reduce risk
The takeaway: “just markdown” isn’t necessarily harmless when an AI agent can act on what it reads.
This is Part 1 of our look at the OWASP Agentic Skills Top 10, covering AST01 through AST05.
—
Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/
Check out Antisyphon Training:
https://www.antisyphontraining.com/
- (00:00) - Intro: OWASP Agentic Skills Top 10, Part 1
- (01:59) - AST01: Malicious Skills
- (06:13) - AST02: Supply Chain Compromise
- (09:37) - AST03: Overprivileged Skills
- (13:56) - AST04: Insecure Metadata
- (16:34) - AST05: Untrusted External Instructions
- (22:36) - Final Takeaways and Part 2 Preview
Click here to watch this episode on YouTube.
Brought to you by:
Black Hills Information Security
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Host
Brian Fehrman
Brian Fehrman is a long-time BHIS Security Researcher and Consultant with extensive academic credentials and industry certifications who specializes in AI, hardware hacking, and red teaming, and outside of work is an avid Brazilian Jiu-Jitsu practitioner, big-game hunter, and home-improvement enthusiast.
Host
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.