These tools are used by Cybersecurity operations teams at the University of Illinois to help assess security risks in code.
This resource helps comply with University of Illinois Cybersecurity standards - including IT-07, IT08, and IT13.
See Cybersecurity Development on the Illinois Knowledge Base for information about our development standards.
- The Cybersecurity Development team at the University of Illinois maintains these AI "skills",
/code-riskand/code-costfor identifying possible vulnerabilities and maintenance costs in local source code. - We update this AI "skill" after OWASP updates the OWASP Top Ten, roughly every four years.
- This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle.
- We consider this skill suitable for exploration and education.
- We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions.
- We recommend also requesting a Code Risk Discussion engagement for more sensitive code, as we find that Code Risk Discussions catch issues that these "skills" cannot.
- Campus faculty and staff responsible for custom code supporting campus users can contact securitysupport@illinois.edu for assistance.
gh skill install techservicesillinois/secdev-code-risk-toolsThen follow the interactive prompts to choose between the available skills, where they should be available, and for which AI engines.
For data sensitivity, see Data Classification.
| Data Store | Data Type | Sensitivity | Notes |
|---|---|---|---|
| Report Files | Descriptions of Code Risks Detected | Sensitive - May contain detected vulnerabilities in a live system. | Developers are encouraged to treat reports files as Traffic Light Protocol:Amber |
| Your AI Agent Training | AI Approved for Campus Use should not train on your source code. Other AI may train on files you allow it to access. | Sensitive | Non-public source code may be Sensitive, and should only be shared with approved AI. |
| Endpoint | Purpose | Stage | Access | Contact |
|---|---|---|---|---|
| Your AI Agent | Applies these patterns to your code to produce reports. | Development | Reads your code and environment | Your AI Agent Vendor |
| OWASP Web Resources | Your agent may access OWASP resources from the OWASP web site to help analyze your code. | Development | Read | https://owasp.org/projects/top-ten |
Only the latest version of this product is supported by Cybersecurity teams at the University of Illinois Urbana-Champaign on a best-effort basis.
As of the last update to this README, the expected End-of-Life and End-of-Support dates of this product are January 2029.
- OWASP updates the Top Ten every four years. Next expected is in 2029.
- Success with these tools will vary by AI tool.