Skip to content

docs(owasp): add third-party attributions to owasp-infrastructure and owasp-mcp#1388

Open
MukundaKatta wants to merge 3 commits intomicrosoft:mainfrom
MukundaKatta:codex/owasp-infrastructure-mcp-attributions
Open

docs(owasp): add third-party attributions to owasp-infrastructure and owasp-mcp#1388
MukundaKatta wants to merge 3 commits intomicrosoft:mainfrom
MukundaKatta:codex/owasp-infrastructure-mcp-attributions

Conversation

@MukundaKatta
Copy link
Copy Markdown
Contributor

@MukundaKatta MukundaKatta commented Apr 20, 2026

Pull Request

Description

owasp-infrastructure and owasp-mcp were the only OWASP skills in this repo that still lacked the Third-Party Attribution section and the OWASP trademark marker already used by owasp-top-10 and owasp-agentic. This PR brings those two skills and their reference files up to the same attribution standard.

Changes included in this PR:

  • Add OWASP® to the affected skill titles and introductory framework references.
  • Add a ## Third-Party Attribution section to both skill SKILL.md files using the same pattern already established elsewhere in the repo.
  • Append matching attribution blocks to the related reference files so the per-reference footer structure is consistent across all OWASP skills.

No vulnerability guidance or remediation content is changed by this PR.

Related Issue(s)

Closes #1325.

Type of Change

Select all that apply:

Code & Documentation:

  • Bug fix (non-breaking change fixing an issue)
  • New feature (non-breaking change adding functionality)
  • Breaking change (fix or feature causing existing functionality to change)
  • Documentation update

Infrastructure & Configuration:

  • GitHub Actions workflow
  • Linting configuration (markdown, PowerShell, etc.)
  • Security configuration
  • DevContainer configuration
  • Dependency update

AI Artifacts:

  • Reviewed contribution with prompt-builder agent and addressed all feedback
  • Copilot instructions (.github/instructions/*.instructions.md)
  • Copilot prompt (.github/prompts/*.prompt.md)
  • Copilot agent (.github/agents/*.agent.md)
  • Copilot skill (.github/skills/*/SKILL.md)

Note for AI Artifact Contributors:

  • Agents: Research, indexing/referencing other project (using standard VS Code GitHub Copilot/MCP tools), planning, and general implementation agents likely already exist. Review .github/agents/ before creating new ones.
  • Skills: Must include both bash and PowerShell scripts. See Skills.
  • Model Versions: Only contributions targeting the latest Anthropic and OpenAI models will be accepted. Older model versions (e.g., GPT-3.5, Claude 3) will be rejected.
  • See Agents Not Accepted and Model Version Requirements.

Other:

  • Script/automation (.ps1, .sh, .py)
  • Other (please describe):

Sample Prompts (for AI Artifact Contributions)

User Request:

Review a change for OWASP infrastructure or MCP risks and cite the relevant framework guidance from the built-in security skills.

Execution Flow:

The skill resolver loads the updated OWASP skill metadata and references, including the new attribution/trademark text, while preserving the existing security guidance content.

Output Artifacts:

No new user-facing artifacts are created. The updated repository artifacts are the touched OWASP SKILL.md files and their reference markdown files.

Success Indicators:

The affected OWASP skill files match the attribution structure already used by the sibling OWASP skills, and the reference files retain the expected footer ordering.

For detailed contribution requirements, see:

Testing

  • Compared the edited skill/reference footers against the existing owasp-top-10 and owasp-agentic patterns.
  • Ran targeted markdown linting expectations against the touched files, noting that .github/skills/** is already excluded by repo configuration.
  • Grepped for OWASP Foundation and OWASP® before and after to confirm the new attribution/trademark coverage matches the intended locations.

Checklist

Required Checks

  • Documentation is updated (if applicable)
  • Files follow existing naming conventions
  • Changes are backwards compatible (if applicable)
  • Tests added for new functionality (if applicable)

AI Artifact Contributions

  • Used /prompt-analyze to review contribution
  • Addressed all feedback from prompt-builder review
  • Verified contribution follows common standards and type-specific requirements

Required Automated Checks

The following validation commands must pass before merging:

  • Markdown linting: npm run lint:md
  • Spell checking: npm run spell-check
  • Frontmatter validation: npm run lint:frontmatter
  • Skill structure validation: npm run validate:skills
  • Link validation: npm run lint:md-links
  • PowerShell analysis: npm run lint:ps
  • Plugin freshness: npm run plugin:generate
  • Docusaurus tests: npm run docs:test

Security Considerations

  • This PR does not contain any sensitive or NDA information
  • Any new dependencies have been reviewed for security issues
  • Security-related scripts follow the principle of least privilege

Additional Notes

  • This keeps the original attribution rationale and verification notes, but moves them into the repository's PR template.
  • The change is limited to attribution/trademark consistency and does not modify framework guidance.

… owasp-mcp

Issue microsoft#1325: owasp-infrastructure and owasp-mcp were the two OWASP
skills shipped without Third-Party Attribution sections or the
OWASP(R) trademark markers that owasp-top-10 and owasp-agentic
already use.

Mirror the owasp-top-10 / owasp-agentic pattern in both skills:

* Add 'OWASP(R)' to the SKILL.md H1 title and to the first paragraph
  that names the framework version.
* Add a 'Third-Party Attribution' section to each SKILL.md with the
  Copyright / CC BY-SA 4.0 / source URL / modifications summary /
  trademark disclaimer block, keyed to each skill's own source URL
  (www-project-top-10-infrastructure-security-risks/ and
  www-project-mcp-top-10/ respectively).
* Append the per-reference CC BY-SA 4.0 attribution block (the same
  'Content derived from works by the OWASP Foundation ...' footer
  owasp-top-10 and owasp-agentic references already carry) to every
  .md under each skill's references/ directory (22 files: 11 per
  skill).

No content changes: only the attribution block and the trademark
(R) markers.

Closes microsoft#1325.
@MukundaKatta MukundaKatta requested a review from a team as a code owner April 20, 2026 03:55
@katriendg
Copy link
Copy Markdown
Contributor

@WilliamBerryiii with changes coming via overall RAI related overhaul, I believe this one because stale?

Copy link
Copy Markdown
Collaborator

@chaosdinosaur chaosdinosaur left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean attribution PR — the Third-Party Attribution sections, H1 trademark markers, and all 22 per-reference CC-BY-SA-4.0 footer blocks match the established sibling pattern exactly. One minor convention nit on body paragraph trademark usage noted inline.

This `SKILL.md` is the **entrypoint** for the OWASP Infrastructure Top 10 skill.

The skill encodes the **OWASP Infrastructure Security Top 10 (2024)** as structured,
The skill encodes the **OWASP® Infrastructure Security Top 10 (2024)** as structured,
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: All five sibling OWASP skills (owasp-top-10, owasp-agentic, owasp-llm, owasp-docker, owasp-cicd) use plain OWASP (no ®) in the body paragraph, reserving ® for the H1 title and the Third-Party Attribution section. This line and the equivalent in owasp-mcp/SKILL.md line 19 introduce OWASP® in the body paragraph, which breaks the convention.

Suggested change
The skill encodes the **OWASP® Infrastructure Security Top 10 (2024)** as structured,
The skill encodes the **OWASP Infrastructure Security Top 10 (2024)** as structured,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(owasp): add thrid-party attributions to skills

3 participants