RiskMandate v1.34.4
OWASP, as a graph

Every OWASP document has its own ontology. Here they are joined.

OWASP is a foundation of projects, each project a set of documents or tools, each document a list of numbered items with its own vocabulary, and each of those pointing at the others and at frameworks outside. This page is that structure as one graph you can zoom through, from the foundation to a single item, with every relationship taken from OWASP’s own pages. Then it joins the graph to the risk model the rest of this section runs on.

Read: OWASP’s own pages, 24 September 2026. Items are titles only. Levels are the live project pages’, and disputed ones are marked.

The data: graph.json, offered to OWASP to take, correct and keep. The bridge to our model is our reading, not OWASP’s.

Zoom

Five levels, one graph.

The fractal part is that each level has the same shape as the one above it: a thing, its parts, and the edges to other things. A reader can stop at any level and still be holding something whole.

1Foundation

OWASP itself.

4Families

How this page groups the projects.

52Projects and documents

Each with its level, type and date.

110Items

The numbered entries of 11 lists.

62Relationships

Stated by OWASP, including 14 frameworks outside it.

Family 1 of 4

The GenAI Security Project

The umbrella project for generative AI and agent security, renamed from the LLM Top 10 project on 26 March 2025, with its own initiatives and documents. The project is Flagship on its live page.

Ten risk categories for applications built on large language models.

10 items, titles only
  1. LLM01:2025 Prompt Injection
  2. LLM02:2025 Sensitive Information Disclosure
  3. LLM03:2025 Supply Chain
  4. LLM04:2025 Data and Model Poisoning
  5. LLM05:2025 Improper Output Handling
  6. LLM06:2025 Excessive Agency
  7. LLM07:2025 System Prompt Leakage
  8. LLM08:2025 Vector and Embedding Weaknesses
  9. LLM09:2025 Misinformation
  10. LLM10:2025 Unbounded Consumption

The edition that replaces 2025, ranked by community vote and incident data, with a different order.

supersedes OWASP Top 10 for LLM Applications 2025
hands agent risks over to OWASP Top 10 for Agentic Applications for 2026 the risk moves to the OWASP Agentic Top 10
maps to GenAI Data Security Risks and Mitigations 2026 v1.0
maps to OWASP AI Vulnerability Scoring System (AIVSS)
maps to MITRE ATLAS
maps to MITRE ATT&CK
maps to MITRE CWE
maps to NIST AI 600-1
maps to NIST AI RMF (AI 100-1)
maps to CSA AI Controls Matrix
LLM08:2026 renames and broadens LLM07:2025 System Prompt Leakage What used to be System Prompt Leakage is now Hidden Context Exposure
OWASP AI Exchange cross-references this
10 items, titles only
  1. LLM01:2026 Prompt Injection
  2. LLM02:2026 Sensitive Information Disclosure
  3. LLM03:2026 Excessive Agency
  4. LLM04:2026 Supply Chain
  5. LLM05:2026 Data and Model Poisoning
  6. LLM06:2026 Unbounded Consumption
  7. LLM07:2026 Misinformation
  8. LLM08:2026 Hidden Context Exposure
  9. LLM09:2026 Vector and Embedding Weaknesses
  10. LLM10:2026 Improper Output Handling

Ten risk categories for agents that plan and act.

relies on Agentic AI – Threats and Mitigations our foundational and detailed taxonomy that this Top 10 relies upon
maps to OWASP Top 10 for LLM Applications 2025
maps to OWASP AI Vulnerability Scoring System (AIVSS)
complemented by CycloneDX (ECMA-424) CycloneDX helps organizations answer, “What components and tools are in my AI system?”
intends to align with OWASP AIBOM
OWASP Top 10 for LLM Applications 2026 hands agent risks over to this
OWASP Non-Human Identities Top 10 mapped to this
OWASP AI Security Verification Standard (AISVS) complements this
Threat Modeling Project references this
AIUC-1 Crosswalk of the Agentic Top 10 maps both ways this
10 items, titles only
  1. ASI01 Agent Goal Hijack
  2. ASI02 Tool Misuse and Exploitation
  3. ASI03 Identity and Privilege Abuse
  4. ASI04 Agentic Supply Chain Vulnerabilities
  5. ASI05 Unexpected Code Execution (RCE)
  6. ASI06 Memory & Context Poisoning
  7. ASI07 Insecure Inter-Agent Communication
  8. ASI08 Cascading Failures
  9. ASI09 Human-Agent Trust Exploitation
  10. ASI10 Rogue Agents

The detailed agent threat taxonomy the Agentic Top 10 relies on.

Guidance for building and deploying agent applications.

The threat taxonomy applied to systems of several agents.

An overview of frameworks and regulation for agents.

A proposed scheme for naming and discovering agents.

supports CSA MAESTRO

Agent Control Standard (ACS)

document1 September 2026

Standard hooks for inspecting and controlling agents at runtime, donated to the project.

Guidance for people who build MCP servers.

Guidance for people who use MCP servers written by others.

GenAI Red Teaming Guide

document22 January 2025

A method for adversarial testing of generative AI systems.

OWASP AI Testing Guide acknowledges this

Questions to ask red-teaming vendors.

A checklist for leaders adopting large language models.

A quarterly map of tools by lifecycle stage, for agents.

The same map, for LLM applications.

The same map, for red-teaming tools.

Data-layer risks for generative AI systems.

Maps the project's risks to controls in outside frameworks.

A two-way mapping between AIUC-1 and the Agentic Top 10.

Threat Defense COMPASS 1.0

document10 September 2025

A worksheet method for prioritising AI threats.

Incident response for generative AI systems.

OWASP AIBOM Generator

document17 December 2025

A tool that writes AI bills of materials in CycloneDX format.

FinBot Agentic AI CTF

document12 August 2025

A deliberately vulnerable agent application for training.

Family 2 of 4

Other OWASP AI projects

AI and agent projects that sit beside the GenAI Security Project, each its own OWASP project.

OWASP AI Exchange

Flagshiplevel disputedDocumentation

Reference guidance on AI threats and controls, continuously updated.

OWASP AI Testing Guide

Incubatorlevel disputedOther

A method and test cases for testing AI systems; v1, 26 November 2025.

A scoring method, starting with agent risks; v0.8.

Testable security requirements for AI systems; 1.0, June 2026.

Ten risk categories for machine-learning systems; the 2023 list, marked in draft.

OWASP AI Exchange aligns with this
10 items, titles only
  1. ML01:2023 Input Manipulation Attack
  2. ML02:2023 Data Poisoning Attack
  3. ML03:2023 Model Inversion Attack
  4. ML04:2023 Membership Inference Attack
  5. ML05:2023 Model Theft
  6. ML06:2023 AI Supply Chain Attacks
  7. ML07:2023 Transfer Learning Attack
  8. ML08:2023 Model Skewing
  9. ML09:2023 Output Integrity Attack
  10. ML10:2023 Model Poisoning

OWASP MCP Top 10

Productionlevel disputedDocumentation

Ten risk categories for MCP systems; a 2025 beta, next release announced for October 2026.

OWASP Agentic Skills Top 10 positions itself beside this
10 items, titles only
  1. MCP01:2025 Token Mismanagement & Secret Exposure
  2. MCP02:2025 Privilege Escalation via Scope Creep
  3. MCP03:2025 Tool Poisoning
  4. MCP04:2025 Software Supply Chain Attacks & Dependency Tampering
  5. MCP05:2025 Command Injection & Execution
  6. MCP06:2025 Intent Flow Subversion
  7. MCP07:2025 Insufficient Authentication & Authorization
  8. MCP08:2025 Lack of Audit and Telemetry
  9. MCP09:2025 Shadow MCP Servers
  10. MCP10:2025 Context Injection & Over-Sharing

Ten risk categories for machine identities: keys, tokens, service accounts; 2025 edition.

10 items, titles only
  1. NHI1:2025 Improper Offboarding
  2. NHI2:2025 Secret Leakage
  3. NHI3:2025 Vulnerable Third-Party NHI
  4. NHI4:2025 Insecure Authentication
  5. NHI5:2025 Overprivileged NHI
  6. NHI6:2025 Insecure Cloud Deployment Configurations
  7. NHI7:2025 Long-Lived Secrets
  8. NHI8:2025 Environment Isolation
  9. NHI9:2025 NHI Reuse
  10. NHI10:2025 Human Use of NHI

OWASP Agentic Skills Top 10

IncubatorDocumentation

Ten risk categories for agent skills, the layer that carries out an agent's actions; in public review.

positions itself beside OWASP MCP Top 10 MCP = how the model talks to tools; AST10 = what those tools actually do.
maps to CSA MAESTRO
10 items, titles only
  1. AST01 Malicious Skills
  2. AST02 Supply Chain Compromise
  3. AST03 Over-Privileged Skills
  4. AST04 Insecure Metadata
  5. AST05 Untrusted External Instructions
  6. AST06 Weak Isolation
  7. AST07 Update Drift
  8. AST08 Poor Scanning
  9. AST09 No Governance
  10. AST10 Cross-Platform Reuse

Inventories of the parts of an AI system.

Family 3 of 4

Standards, lists and guides an agent deployment touches

OWASP work that predates agents but applies to the systems they run in and call.

OWASP ASVS

FlagshipStandards

Security requirements for web applications; 5.0.0, May 2025.

OWASP SAMM

FlagshipStandards

A maturity model for software security programmes; v2.0.

OWASP Top 10: 2025 references this

OWASP Top 10: 2025

FlagshipDocumentation

Ten web application risk categories; the 2025 edition.

references OWASP ASVS
references OWASP SAMM
A03:2025 references CycloneDX (ECMA-424)
A03:2025 references Dependency-Track
Core Rule Set (CRS) defends against this
10 items, titles only
  1. A01:2025 Broken Access Control
  2. A02:2025 Security Misconfiguration
  3. A03:2025 Software Supply Chain Failures
  4. A04:2025 Cryptographic Failures
  5. A05:2025 Injection
  6. A06:2025 Insecure Design
  7. A07:2025 Authentication Failures
  8. A08:2025 Software or Data Integrity Failures
  9. A09:2025 Security Logging and Alerting Failures
  10. A10:2025 Mishandling of Exceptional Conditions

OWASP API Security Top 10

Productionlevel disputedDocumentation

Ten API risk categories; the 2023 edition.

recommends OWASP ASVS
10 items, titles only
  1. API1:2023 Broken Object Level Authorization
  2. API2:2023 Broken Authentication
  3. API3:2023 Broken Object Property Level Authorization
  4. API4:2023 Unrestricted Resource Consumption
  5. API5:2023 Broken Function Level Authorization
  6. API6:2023 Unrestricted Access to Sensitive Business Flows
  7. API7:2023 Server Side Request Forgery
  8. API8:2023 Security Misconfiguration
  9. API9:2023 Improper Inventory Management
  10. API10:2023 Unsafe Consumption of APIs

CycloneDX (ECMA-424)

FlagshipStandards

A bill-of-materials standard with a machine-learning variant; specification 1.7.

Supply-chain verification controls; 1.0.

Ten build-pipeline risk categories.

10 items, titles only
  1. CICD-SEC-1 Insufficient Flow Control Mechanisms
  2. CICD-SEC-2 Inadequate Identity and Access Management
  3. CICD-SEC-3 Dependency Chain Abuse
  4. CICD-SEC-4 Poisoned Pipeline Execution (PPE)
  5. CICD-SEC-5 Insufficient PBAC (Pipeline-Based Access Controls)
  6. CICD-SEC-6 Insufficient Credential Hygiene
  7. CICD-SEC-7 Insecure System Configuration
  8. CICD-SEC-8 Ungoverned Usage of 3rd Party Services
  9. CICD-SEC-9 Improper Artifact Integrity Validation
  10. CICD-SEC-10 Insufficient Logging and Visibility

Kubernetes Top Ten

IncubatorDocumentation

Ten Kubernetes risk categories; the 2025 list.

10 items, titles only
  1. K01 Insecure Workload Configurations
  2. K02 Overly Permissive Authorization Configurations
  3. K03 Secrets Management Failures
  4. K04 Lack Of Cluster Level Policy Enforcement
  5. K05 Missing Network Segmentation Controls
  6. K06 Overly Exposed Kubernetes Components
  7. K07 Misconfigured And Vulnerable Cluster Components
  8. K08 Cluster To Cloud Lateral Movement
  9. K09 Broken Authentication Mechanisms
  10. K10 Inadequate Logging And Monitoring

Cheat Sheet Series

FlagshipDocumentation

Short guides, one topic each.

bridges to OWASP ASVS

Threat Modeling Project

Lablevel disputedDocumentation

The entry point for OWASP's threat-modelling guidance, including agentic threat modelling.

Family 4 of 4

Tools

Software an organisation can run, several with a business case on this site.

Threat models as data-flow diagrams.

pytm

ProductionCodebusiness case

Threat models written as Python code.

A web application firewall engine.

compatible with Core Rule Set (CRS) 100% compatible with OWASP Core Ruleset

Detection rules for web application firewalls.

defends against OWASP Top 10: 2025
Coraza Web Application Firewall compatible with this

Dependency-Track

FlagshipTool

Tracks component risk from bills of materials.

Dependency-Check

FlagshipTool

Finds known vulnerable dependencies.

DefectDojo

FlagshipTool

Collects and manages security findings.

Juice Shop

FlagshipTool

A deliberately vulnerable web application for training.

WrongSecrets

ProductionTool

Secrets-management training exercises.

Outside OWASP

The frameworks OWASP maps to, titles only.

NIST AI 600-1

CSA AI Controls Matrix

ISO/IEC 27090

OWASP AI Exchange feeds into this

AIUC-1

Google SAIF

NIST AML taxonomy

CSA MAESTRO

ZAP (left OWASP, 1 August 2023)

left OWASP Foundation ZAP can only be in one foundation, so regretfully ZAP will be leaving OWASP.
Where OWASP meets our model

The Agentic Top 10, joined to the register.

For each item, the answers in our model that bound it, the risks those answers establish, and the open-source cases on this site that change those answers. This is our reading, stated as ours. Three items touch nothing in the model; that is a finding about the model, and it says where the model has to grow.

ItemThe answers that bound itModel risksCases that change those answers
ASI01 Agent Goal HijackCan it change things in production, or only read and report?
Can it reach anything outside your network?
What can it do with that data?A hijacked agent does what its reach allows: the answers that bound it are whether it changes things on its own, where it can send data, and what it can do to the data in reach.
RISK-15 the organisation acts through a system that acts without a person approving each action
RISK-28 the agent can reach systems outside the estate
RISK-16 regulated data is modifiable by an agent
agentgateway, Cedar, Cilium network policy, gVisor, LangGraph and LangChain human-in-the-loop, LiteLLM, Open Policy Agent, OpenFGA, Squid
ASI02 Tool Misuse and ExploitationWhat can it do with that data?
Can it change things in production, or only read and report?
Could its worst change be undone?Misuse of a tool is bounded by what the tool may change, whether a person approves it, and whether the change can be undone.
RISK-16 regulated data is modifiable by an agent
RISK-6 the production estate can be changed by an agent
RISK-22 some changes the agent makes cannot be reversed by the operator
agentgateway, Cedar, LangGraph and LangChain human-in-the-loop, LiteLLM, Open Policy Agent, OpenFGA, PostgreSQL point-in-time recovery, Velero
ASI03 Identity and Privilege AbuseWhose account does it act under?
If it misbehaved at full speed, what could it reach?Whose account the agent acts under, and whether anybody can state what it is entitled to reach.
RISK-14 the agent's actions cannot be attributed to a person
RISK-8 the operator cannot state what the agent is entitled to reach
RISK-17 the scope of the agent's access cannot be reviewed
Keycloak, OWASP Threat Dragon and pytm
ASI04 Agentic Supply Chain Vulnerabilitiesnot in the modelNot in the model: none of its sixteen questions asks where the agent's components came from.––
ASI05 Unexpected Code Execution (RCE)Can it reach anything outside your network?
Can it change things in production, or only read and report?Code the agent runs reaches what the agent can reach; isolation and egress are the answers that bound it.
RISK-28 the agent can reach systems outside the estate
RISK-6 the production estate can be changed by an agent
agentgateway, Cilium network policy, gVisor, LangGraph and LangChain human-in-the-loop, Squid
ASI06 Memory & Context Poisoningnot in the modelNot in the model: it has no question about what the agent remembers or which context it trusts.––
ASI07 Insecure Inter-Agent Communicationnot in the modelNot in the model: it describes one agent, not agents talking to each other.––
ASI08 Cascading FailuresDo you know the side effects of stopping it?
If you had to stop it right now — could you?Whether the side effects of stopping are known, and whether stopping is one action.
RISK-10 what else stops when the agent stops is unknown to the people who would stop it
RISK-20 the dependency map behind the stop control is incomplete
RISK-30 using the stop control has consequences the estate has not mapped
RISK-2 stopping the agent is itself a service interruption
OpenBao, Unleash
ASI09 Human-Agent Trust ExploitationDoes its output affect a decision about a person?
Can it change things in production, or only read and report?Whether the agent's output decides about a person, and whether a person approves each change.
RISK-34 oversight of a decision about a person may be nominal rather than real
RISK-27 a decision about a person is made without a person making it
LangGraph and LangChain human-in-the-loop
ASI10 Rogue AgentsIf you had to stop it right now — could you?
How long would stopping actually take?
Have you ever actually stopped it?
Could you reconstruct what it did last Tuesday?Whether it can be stopped, how fast, whether that has ever been done, and whether what it did can be read back.
RISK-35 the agent cannot be stopped
RISK-9 stopping the agent takes more than one action
RISK-38 the estate has no demonstrated means of interrupting the agent
RISK-13 what the agent did cannot be reconstructed
agentgateway, Falco, Langfuse, Open Policy Agent, OpenBao, OWASP Coraza, Unleash
Where OWASP’s pages disagree

Published unresolved, for the projects to settle.

Why this is here, and where it should live

A graph OWASP does not have yet, offered to OWASP.

The lead is closely involved with OWASP, and the intent is to offer this graph, and in time the Agent Behaviour Policy format, to OWASP rather than keep them here. Until then the data is published so anybody can take it, and it changes with a date when a project corrects it.

From a list to a register

An item names a risk. A behaviour policy says whether yours has it.

The Top 10s say what can go wrong with agents in general. What goes wrong with yours depends on what it can reach, which is what a behaviour policy writes down, and which projects change it, which is what the business cases compute.