The OWASP GenAI Security Project released its Top 10 for Agentic Applications, a list of ten risk categories specific to agents that plan, hold memory, call tools and act with delegated authority. The release came with an updated Agentic Threats and Mitigations taxonomy (v1.1) and a capture-the-flag practice platform.
Why it matters
It is OWASP's agent-specific risk list, complementing its Top 10 for LLM applications.
Key facts
As stated in the sources, with where to find them.
- ASI01 Agent Goal Hijack; ASI02 Tool Misuse; ASI03 Identity & Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution; ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents.Release post, list
- Released with Agentic Threats & Mitigations v1.1, the FinBot CTF platform, and integration with the AI Vulnerability Scoring Standard (AIVSS).Release post, complementary resources
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Feb 17, 2025
Sep 30, 2025
Nov 17, 2024
Nov 19, 2025
Feb 17, 2026
Aug 14, 2025