OWASP / OWASP/wrongsecrets

MOAR AI def issues

Open
#2,656 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

New Challenge
Dominant language
HTML
Stars
1.5k
Forks
625
Avg merge
14h 21m
Merged PRs (30d)
44

Description

Context
  • What should the challenge scenario be like?
    Agent instruction/context files: CLAUDE.md, AGENTS.md, .cursor/rules, .windsurfrules, etc. can contain real credentials added as persistent context and then accidentally committed. This generalizes the skill-file challenge to the wider ecosystem. We already have skills.md so now we need to add it to others.
  • What should the participant learn from completing the challenge?
    be careful what you put in agents.md/rules/etc.
  • For what category would the challenge be? (e.g. Docker, K8s, binary)
    AI
Did you encounter this in real life? Could you tell us more about the scenario?

yes

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the existing skills.md challenge and compare it with the agent instruction/context filenames listed in the issue: CLAUDE.md, AGENTS.md, .cursor/rules, and .windsurfrules. Add a corresponding AI challenge showing how credentials in these files can be accidentally committed, with completion teaching participants to avoid placing secrets there.

Written by the indexing model from the issue text.

Assessment

Domain
ai-infra-agents, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.