TwinEthos homeAPI access

Catalog

OWASP Agentic Top 10 (2026)

OWASP GenAI Security Project · pack 0.2.0 · verified against the official source as of 2026-10-04. Open it in the explorer.

Standard / soft law

Agent-to-agent and tool-server channels should be authenticated, signed and replay-protected

OWASP ASI07 (Insecure Inter-Agent Communication, guidelines 1, 2 and 3) asks for encrypted channels with per-agent credentials and mutual authentication, signed and integrity-checked messages, and replay protection with nonces and session identifiers; ASI04 (Agentic Supply Chain Vulnerabilities, guideline 5) asks for mutual authentication and attestation between agents. Every MCP, A2A or tool-server endpoint authenticates its callers and every client reaches a fixed, expected server over TLS. Detect MCP servers reached over plain HTTP or without credentials, tool servers that accept unauthenticated callers, and A2A peers without authentication or signing.

owasp-agentic-top10.authenticated-inter-agent-channels · OWASP Top 10 for Agentic Applications for 2026 — ASI07: Insecure Inter-Agent Communication: Prevention and Mitigation Guidelines, guidelines 1, 2 and 3 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent runs should have budgets, fan-out caps and circuit breakers

OWASP ASI08 (Cascading Failures, guidelines 6 and 7) asks that activity spreading quickly across agents be throttled, and that limits stop one failure from reaching further (quotas, caps on progress, circuit breakers), and ASI02 (Tool Misuse and Exploitation, guideline 5) for cost, rate or token budgets on tool use. Each agent run has a step limit, caps how many tool calls one step may launch, and stops at a spend ceiling. Detect agent loops with no step limit, unbounded parallel tool fan-out over model-chosen lists, and missing spend caps.

owasp-agentic-top10.bounded-agent-fan-out-and-budgets · OWASP Top 10 for Agentic Applications for 2026 — ASI08: Cascading Failures: Prevention and Mitigation Guidelines, guidelines 6 and 7 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent components, tools and prompts should be inventoried, allowlisted and pinned

OWASP ASI04 (Agentic Supply Chain Vulnerabilities, guidelines 1, 2 and 7) asks for signed manifests and bills of materials covering prompts, tools and agents, allowlisted and pinned dependencies, and prompts, tools and configurations pinned by content hash or commit. The agent keeps a machine-readable inventory of its models, MCP servers, peers, tools and skills and pins each one. An OWASP Agent Control Standard AgBOM is accepted as the inventory. Detect AI SDK, agent-framework and MCP-server dependencies without a pinned version, and the absence of any AI component inventory.

owasp-agentic-top10.component-provenance-and-pinning · OWASP Top 10 for Agentic Applications for 2026 — ASI04: Agentic Supply Chain Vulnerabilities: Prevention and Mitigation Guidelines, guidelines 1, 2 and 7 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

High-impact agent actions should need an explicit confirmation that shows the exact effect

OWASP ASI09 (Human-Agent Trust Exploitation, guidelines 1 and 7) asks for explicit, possibly multi-step confirmation before sensitive actions and for previews that cannot cause effects; ASI02 (guideline 2) and ASI03 (guideline 4) ask for approval of high-risk tool actions and privilege escalation. The approval step sits in the executor before the effect, shows the exact command, arguments, recipient or amount, and cannot be bypassed by configuration. Detect model-selected tool calls that reach destructive, financial or externally visible operations with no approval, approval bypass settings, and summary-only approval prompts.

owasp-agentic-top10.human-confirmation-high-impact-actions · OWASP Top 10 for Agentic Applications for 2026 — ASI09: Human-Agent Trust Exploitation: Prevention and Mitigation Guidelines, guidelines 1 and 7 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent tools and credentials should be task-scoped, short-lived and re-authorized on each action

OWASP ASI02 (Tool Misuse and Exploitation, guideline 1) asks for least-privilege profiles per tool, and ASI03 (Identity and Privilege Abuse, guidelines 1, 2 and 3) for narrowly scoped, time-bound credentials, separated agent identities and contexts, and authorization re-checked on every privileged step. Each agent gets only the tools and credentials its task needs, runs tool calls in the requesting user's delegated context, and the executor re-authorizes each call. Detect wildcard tool grants, unrestricted shell or code tools, broad cloud or database roles, and tools that use one shared service credential for all users.

owasp-agentic-top10.least-privilege-tools-and-identity · OWASP Top 10 for Agentic Applications for 2026 — ASI02: Tool Misuse and Exploitation: Prevention and Mitigation Guidelines, guideline 1 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Writes to agent memory should be validated, attributable and expire when unverified

OWASP ASI06 (Memory & Context Poisoning, guidelines 2, 6 and 8) asks that content be checked before it is committed to memory, that what the agent itself produced is not fed back into its trusted memory without a check, and that memory nobody verified ages out. Memory is written only on the user's explicit intent or by trusted system logic, each item records its source, and items have a retention limit. Detect memory-write tools a model can call in a turn that includes untrusted content, with no user confirmation or provenance gate.

owasp-agentic-top10.memory-write-validation · OWASP Top 10 for Agentic Applications for 2026 — ASI06: Memory & Context Poisoning: Prevention and Mitigation Guidelines, guidelines 2, 6 and 8 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent-generated code and commands should never reach an interpreter unvalidated

OWASP ASI05 (Unexpected Code Execution, guidelines 1 and 3) asks for the output-handling controls of the LLM Top 10 on everything an agent generates, and rules out eval of model output in production agents in favour of safe interpreters and taint tracking. Generated code runs only in an isolated sandbox, and model-derived values reach shells and databases only as argument lists and parameters. Detect model output that reaches eval or exec, a shell, string-built SQL or raw HTML rendering.

owasp-agentic-top10.no-unvalidated-code-execution · OWASP Top 10 for Agentic Applications for 2026 — ASI05: Unexpected Code Execution (RCE): Prevention and Mitigation Guidelines, guidelines 1 and 3 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent system prompts and goal definitions should change only through a reviewed, evaluated release

OWASP ASI01 (Agent Goal Hijack, guideline 3) asks that an agent's system prompt make its goal priorities and permitted actions explicit and auditable, and that changes to goals or reward definitions pass configuration management and human approval. Prompts and goal definitions live in version control, and a change to them triggers the evaluation suite in CI and cannot ship on a failing run. Detect a repository with no evaluation job triggered by prompt or model-configuration changes.

owasp-agentic-top10.prompt-and-goal-change-control · OWASP Top 10 for Agentic Applications for 2026 — ASI01: Agent Goal Hijack: Prevention and Mitigation Guidelines, guideline 3 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent behavior should be monitored, with a kill switch and fixed authority

OWASP ASI10 (Rogue Agents, guidelines 3 and 4) asks for behavioral monitoring that can spot an agent acting outside its role and for fast containment, such as kill switches and credential revocation. The agent's maximum authority is fixed before the run, alerts fire on out-of-scope egress, credential use or identity creation, and a runtime halt stops the agent. Detect agent deployments with no behavioral alerts, automatic halt or incident procedure, and agents able to widen their own allowlists.

owasp-agentic-top10.rogue-agent-detection-and-containment · OWASP Top 10 for Agentic Applications for 2026 — ASI10: Rogue Agents: Prevention and Mitigation Guidelines, guidelines 3 and 4 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent tool and code execution should run in a sandbox with enforced egress limits

OWASP ASI02 (Tool Misuse and Exploitation, guideline 3) asks that tools and code run in isolation with outbound network limits, and ASI05 (Unexpected Code Execution, guideline 4) that generated code run without root privileges, inside a container, with little or no network reach. The runtime, not the agent, fixes which hosts the agent can reach and which credentials it holds. Detect agent containers on the host network or with unrestricted egress, and long-lived credentials placed in the agent's environment.

owasp-agentic-top10.sandboxed-execution-and-egress · OWASP Top 10 for Agentic Applications for 2026 — ASI02: Tool Misuse and Exploitation: Prevention and Mitigation Guidelines, guideline 3 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Agent actions should be recorded in a tamper-evident security log

OWASP ASI10 (Rogue Agents, guideline 1), ASI09 (Human-Agent Trust Exploitation, guideline 2) and ASI08 (Cascading Failures, guideline 10) ask for immutable, signed records of agent actions, tool calls, inter-agent messages and policy decisions, so that what an agent did can be reconstructed and attributed. Every model call and tool call emits a security event to an append-only or signed store with bounded retention and restricted access. Detect agent repositories with no AI tracing or audit instrumentation.

owasp-agentic-top10.tamper-evident-agent-action-logs · OWASP Top 10 for Agentic Applications for 2026 — ASI10: Rogue Agents: Prevention and Mitigation Guidelines, guideline 1 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule

Standard / soft law

Content an agent reads should not be able to redirect its goals or trigger its tools

OWASP ASI01 (Agent Goal Hijack, guidelines 1 and 6) asks that every natural-language input an agent receives, from users, documents, retrieved content, e-mail, calendars or tool output, be treated as untrusted, and that connected data sources be sanitized before they can influence goal selection or tool use. Untrusted content stays in a separate, labelled data channel and never in the instruction context of a turn that holds high-impact tools. Detect fetched, uploaded or retrieved content concatenated into system prompts or instructions of a tool-holding agent.

owasp-agentic-top10.untrusted-input-goal-hijack · OWASP Top 10 for Agentic Applications for 2026 — ASI01: Agent Goal Hijack: Prevention and Mitigation Guidelines, guidelines 1 and 6 · official source · jurisdictions: INTL

The guard to add, and how far to trust this rule