HOME
OWASP Foundation, the Open Source Foundation for Application Security on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
ABOUT
About the OWASP Foundation on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
PROJECTS
Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic. The aim of this project is to take AppSec novices or experienced engineers and sharpen their penetration testing skillset to security expert status. ... The OWASP Top 10 is the ...
CHAPTERS
OWASP Local Chapters on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
🌐
OWASP
genai.owasp.org β€Ί home β€Ί llmrisks
LLMRisks Archive - OWASP Gen AI Security Project
Expore the latest Top 10 risks, vulnerabilities and mitigations for developing and securing generative AI and large language model applications across the development, deployment and management lifecycle.
Discussions

OWASP Top 10 for LLMs: What Every Beginner in AI & Cybersecurity Must Know
This, "Some require stricter input validation. Some require limiting what the AI is allowed to do. Some require better monitoring of what the model is actually producing at runtime." Top down rules of engagement, syslogs of everything, geo fencing each action, with humans in the loop. Do not forget agency... basic stuff friends, its their for a reason. Go to the basics, it helps More on reddit.com
🌐 r/pwnhub
7
5
March 29, 2026
OWASP published its first Top 10 for AI Agents. 88% of enterprises already had agent security incidents last year. Here's the breakdown.
Once agents access tools, memory, APIs, and other agents, the problem becomes security architecture, not chatbot mistakes. One poisoned prompt or tool can ripple through entire systems fast. Platforms like Runable feel aligned with solving that orchestration and visibility layer. More on reddit.com
🌐 r/artificial
9
5
May 21, 2026
OWASP updated their Top 10 - a brand new #3
Broken access control stays NR. 1 Just the following three sink. Supply chain is a very relevant addition. And, in parts, logical. When design and injection etc go down, supply chain which has less controls goes up. I like it :) More on reddit.com
🌐 r/cybersecurity
14
108
November 12, 2025
AI Security: The OWASP Top 10 LLM Risks Every Developer Should Know
the ide threat surface point is real, my exoclaw agent runs on its own isolated server so at least the ai execution is sandboxed away from my dev environment More on reddit.com
🌐 r/ArtificialInteligence
5
3
April 12, 2026
🌐
OWASP
genai.owasp.org β€Ί home
Home - OWASP Gen AI Security Project
3 weeks ago - As organizations increasingly deploy generative AI and autonomous agents into business-critical workflows, traditional application security practices are no longer sufficient. AI systems introduce new classes of ... As co-lead of OWASP ASI06: Memory & Context Poisoning entry as part of OWASP Top 10 ...
🌐
Alexewerlof
blog.alexewerlof.com β€Ί alex ewerlΓΆf notes β€Ί owasp top 10 agents & ai vulnerabilities (2026 cheat sheet)
OWASP Top 10 Agents & AI Vulnerabilities (2026 Cheat Sheet)
March 20, 2026 - The JS/Serverless Reality: If you deploy a Node.js Lambda function as an AI tool to interact with your database, and the execution role has DynamoDB:PutItem but the agent only needs to read, a prompt injection can wipe your table. Who needs backups when you have velocity?
🌐
OWASP
genai.owasp.org β€Ί home β€Ί resources β€Ί owasp top 10 for agentic applications for 2026
OWASP Top 10 for Agentic Applications for 2026 - OWASP Gen AI Security Project
December 10, 2025 - The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems. Developed through extensive collaboration with more than 100 industry ...
🌐
Trend Micro
trendmicro.com β€Ί en_us β€Ί what-is β€Ί ai β€Ί owasp-top-10.html
What are the OWASP Top 10 risks for LLMs? | Trend Micro (US)
The OWASP Top 10 for LLMs warns of risks like prompt injection, data leakage, and insecure plugins. Trend Vision Oneβ„’ helps organizations address these challenges with: AI Application Security – Blocks malicious prompts and plugin exploits.
🌐
Reddit
reddit.com β€Ί r/pwnhub β€Ί owasp top 10 for llms: what every beginner in ai & cybersecurity must know
r/pwnhub on Reddit: OWASP Top 10 for LLMs: What Every Beginner in AI & Cybersecurity Must Know
March 29, 2026 -

When a company builds a product powered by a large language model, they tend to focus on what the AI can do, not on how it can be exploited.

AI systems introduce a new category of vulnerabilities that traditional security checklists do not cover. An attacker can manipulate an AI by slipping instructions into its input, trick it into leaking sensitive data from its training, or overwhelm it with requests that drain resources and drive up costs, none of which map cleanly onto the security risks that developers already know to look for.

OWASP, the nonprofit organization that maintains the most widely used security risk framework in software development, publishes a dedicated Top 10 list for large language model applications. It covers threats like prompt injection, where a malicious user rewrites the AI's instructions through ordinary text input; excessive agency, where an AI with too many permissions takes actions its designers never intended; and data poisoning, where corrupted training data plants hidden behaviors in the model before it ever reaches users.

The fix for each risk varies. Some require stricter input validation. Some require limiting what the AI is allowed to do. Some require better monitoring of what the model is actually producing at runtime.

This writeup walks through all ten risks in plain language, making it a useful entry point for anyone building with AI who wants to understand the attack surface before something goes wrong.

🌐
Practical DevSecOps
practical-devsecops.com β€Ί home β€Ί owasp top 10 for agentic applications for 2026
OWASP Top 10 for Agentic Applications for 2026 - Practical DevSecOps
June 3, 2026 - A standard LLM generates content like text or code. An agentic AI takes that a step further. It uses tools, makes decisions, and performs multi-step tasks autonomously in a digital or physical environment.
Find elsewhere
🌐
DeepTeam
trydeepteam.com β€Ί docs β€Ί frameworks-owasp-top-10-for-agentic-applications
OWASP Top 10 for Agents 2026 | DeepTeam - The LLM Red Teaming Framework
June 5, 2026 - Use the OWASP ASI Top 10 to assess agentic-specific risks like tool orchestration, inter-agent communication, and cascading failures Β· This dual approach ensures comprehensive coverage from model-level vulnerabilities to system-level agentic risks. The OWASP ASI framework is specifically designed for: Autonomous AI agents with planning and reasoning capabilities
🌐
F5
f5.com β€Ί glossary β€Ί owasp-top-10-for-agentic-ai-applications
OWASP Top 10 for Agentic Applications: Securing Agentic AI with F5 | F5
June 19, 2026 - The OWASP Agentic AI Top 10 highlights the most critical security risks associated with autonomous and semi-autonomous AI systems. Many of these risks do not exist solely within the model. They emerge across the broader application architecture, including APIs, data flows, third-party tools, identity controls, and runtime actions.
🌐
Microsoft
microsoft.com β€Ί blog home β€Ί addressing the owasp top 10 risks in agentic ai with microsoft copilot studio
Addressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio | Microsoft Security Blog
April 1, 2026 - Organizations that treat agents as privileged applications, with clear identities, scoped permissions, continuous oversight, and lifecycle governance, are better positioned to manage and reduce risk as they adopt agentic AI. Establishing governance early allows teams to scale innovation confidently, rather than retroactively building controls after the agents are embedded in workflows. Here are some resources to look over as the next step in your journey: OWASP Top 10 for Agentic Applications (2026): The baseline: top risks for agentic systems, with examples and mitigations.
🌐
OWASP
owasp.org β€Ί www-project-agentic-skills-top-10
OWASP Agentic Skills Top 10 | OWASP Foundation
March 9, 2026 - The OWASP Agentic Skills Top 10 (AST10) documents the 10 most critical security risks in agentic AI skills across all major AI agent platforms.
🌐
Reddit
reddit.com β€Ί r/artificial β€Ί owasp published its first top 10 for ai agents. 88% of enterprises already had agent security incidents last year. here's the breakdown.
r/artificial on Reddit: OWASP published its first Top 10 for AI Agents. 88% of enterprises already had agent security incidents last year. Here's the breakdown.
May 21, 2026 -

OWASP released the Top 10 for Agentic Applications in December 2025 - the first formal risk taxonomy for autonomous AI agents. Not chatbots. Not copilots. Agents that plan, use tools, maintain memory, and act without waiting for permission.

Some numbers for context:

  • 88% of enterprises reported AI agent security incidents in the last 12 months (Gravitee survey, 919 respondents)

  • Only 21% have runtime visibility into what their agents are doing

  • 82% of enterprises have unknown agents in their environments (Cloud Security Alliance, April 2026)

  • 5.5% of public MCP servers contain poisoned tool descriptions. 84.2% attack success rate with auto-approval enabled.

Here's the list with the real attacks behind each one:

ASI01 - Agent Goal Hijack: Prompt injection for agents. Researchers showed this against GitHub's MCP integration - a malicious GitHub issue redirected a coding agent to exfiltrate data from private repos. The agent looked like it was working normally the whole time.

ASI02 - Tool Misuse: A financial services agent was tricked into running a regex that matched every customer record. 45,000 records exported through one syntactically valid tool call. The agent had permission to query records - just not all of them at once.

ASI03 - Identity and Privilege Abuse: Agents inherit user permissions and cache credentials. Compromise one agent in a delegation chain and you get the combined permissions of every user in that chain.

ASI04 - Supply Chain Compromise: OX Security found 7,000+ vulnerable MCP servers and packages totaling 150M+ downloads affected by architectural flaws in Anthropic's MCP SDKs across Python, TypeScript, Java, and Rust.

ASI05 - Unexpected Code Execution: Check Point demonstrated RCE in Claude Code through poisoned .claude config files in repos. Open the repo, agent reads the config, executes the payload with full developer permissions.

ASI06 - Memory Poisoning: Galileo AI found that one compromised agent poisoned 87% of downstream decision-making within 4 hours in multi-agent systems. Morris-II showed self-replicating adversarial prompts spreading through RAG systems. Demonstrated live against ChatGPT, Gemini, and Claude.

ASI07 - Insecure Inter-Agent Comms: Multi-agent systems coordinate via message buses and shared memory. No authentication = agent-in-the-middle attacks in natural language.

ASI08 - Cascading Failures: Natural language errors pass validation checks that would catch malformed data in typed systems. One bad input ripples through the entire agent chain faster than humans can intervene.

ASI09 - Human-Agent Trust Exploitation: Compromised agent presents a clean summary - "approve this data export." Human clicks OK. Audit trail shows human approval. Real origin was a manipulated agent.

ASI10 - Rogue Agents: The insider threat equivalent for AI. Individual actions look legitimate. Only detectable through behavioral monitoring over time.

The pattern: these are not independent risks. They form a kill chain. Goal hijack leads to tool misuse. Supply chain compromise enables code execution and memory poisoning. Trust exploitation is how rogue agents avoid detection.

Full OWASP document here

🌐
Snyk Learn
learn.snyk.io β€Ί learning-paths β€Ί owasp-top-10-llm
OWASP Top 10 LLM and GenAI | Snyk Learn
October 15, 2025 - The Open Web Application Security Project (OWASP) has identified and addressed the most critical security risks in software development. With the rapid rise of Large Language Models (LLMs) and generative AI, OWASP has extended its expertise to highlight the top 10 security concerns specific to these advanced AI systems.
🌐
GitHub
github.com β€Ί owasp β€Ί www-project-top-10-for-large-language-model-applications
GitHub - OWASP/www-project-top-10-for-large-language-model-applications: OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project) Β· GitHub
This repository contains the OWASP Top 10 for Large Language Model Applications, which is now housed under the comprehensive OWASP GenAI Security Project. The OWASP GenAI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI ...
Starred by 1.3K users
Forked by 334 users
Languages Β  Python 46.0% | TeX 25.1% | CSS 12.1% | Makefile 5.7% | TypeScript 4.7% | Jupyter Notebook 2.5%
🌐
OWASP
genai.owasp.org β€Ί home β€Ί blog β€Ί owasp top 10 for agentic applications – the benchmark for agentic security in the age of autonomous ai
OWASP Top 10 for Agentic Applications - The Benchmark for Agentic Security in the Age of Autonomous AI - OWASP Gen AI Security Project
December 10, 2025 - A shared language mapping with our Top 10 for LLMs and other efforts including the AI Vulnerability Scoring Standard (AI-VSS). A clear actionable path forward for securing agentic systems at the pace of innovation. Today, with immense pride, we release the OWASP Top 10 for Agentic AI Applications-a milestone shaped by hundreds of experts who understood that securing this new frontier requires not just content, but clarity, courage, and community.
🌐
Owaspai
owaspai.org β€Ί docs β€Ί ai_security_overview
0. AI Security Overview – AI Exchange
The OWASP GenAI Security Project is an umbrella project of various initiatives that publish documents on Generative AI security, including the LLM AI Security & Governance Checklist and the LLM top 10 - featuring the most severe security risks of Large Language Models.
🌐
Medium
idanhabler.medium.com β€Ί demystifying-owasp-top-10-for-agentic-ai-36aee157a3f9
Demystifying OWASP Top 10 for Agentic AI | by Idan Habler | Medium
December 12, 2025 - Agentic AI is emerging from the lab and into real-world applications like banking, healthcare, critical infrastructure, and the public sector. When agents can plan, decide, and act across tools and systems, a single error (or attacker) can cascade throughout an organization. To help teams reason about those risks, the OWASP Agentic Security Initiative (ASI) project published the OWASP Top 10 for Agentic Applications β€” a threat-focused list of the most important things that can go wrong in agentic systems, plus concrete mitigations teams can apply today.
🌐
YouTube
youtube.com β€Ί watch
Deep Dive into the OWASP Top 10 for Agentic AI Applications - John Sotiropoulos - YouTube
"Deep Dive into the OWASP Top 10 for Agentic Applications" - John SotiropoulosJoin John Sotiropoulos from the OWASP GenAI Security Project's Agentic Security...
Published Β  November 23, 2025