OWASP Agentic Top 10 — coverage

A map of how OAP addresses the OWASP Top 10 for Agentic Applications (2026). Each concept in these docs is designed around specific threats below; each threat here names the OAP mechanism that answers it and the gaps that remain. This is an advisory assessment, not a certification — coverage is a qualitative judgement, and honest about what's missing.

Across the ten: 4 substantially addressed · 6 partial.

ASI01 — Agent Goal Hijack Partial

What OAP does. Tool output cannot widen what the agent may do: every resulting action is checked outside the model, and high-impact and external actions can be human-approval-gated. Tool results are the only non-user ingress path; as a secondary aid, each is wrapped in an unpredictable per-result nonce and the system prompt's spotlighting rule tells the model to treat delimited content as data, never instructions. A pluggable content-guard seam inspects tool I/O, and two inspectors ship: a prompt-injection classifier (run in a zero-egress pod) and a URL allowlist. — see Safe tools, Content guards & egress, and Agent definition.

Gaps. No goal-lock or plan-divergence detection; inspection covers tool I/O, not the agent's own replies.

ASI02 — Tool Misuse & Exploitation Substantial

What OAP does. This is OAP's home turf. Tools are dual-validated — at authoring time and again at execution time — behind deny-by-default subcommand/field allowlists and CEL, and they run as argv arrays, never through a shell. Each tool's stateImpact (readonly / readwrite / external) drives the authorization check and whether a human is asked; every action is checked per-action against SpiceDB. Secrets are scrubbed from output; default-on circuit breakers, plus opt-in per-tool rate limits and per-call data-volume budgets, bound runaway use. — see Safe tools.

Gaps. Egress control is L3/L4 only; the volume budget is per-call, not cumulative.

ASI03 — Identity & Privilege Abuse Substantial

What OAP does. Each agent has its own AgentIdentity — there is no shared credential catalog. Acting on a user's behalf goes through UserIdentity → SessionUserIdentity with the credential set narrowed to what the session's agent asked for, and a token broker resolves credentials just-in-time (a valet key, fail-closed). Critically, an agent never acts on authority of its own: checks run against the user it acts for, or, for a session with no user, a principal of its own (the session itself, or a service it declares) with no standing grants — which structurally blocks the confused-deputy problem; grants are bound to an arguments-hash HMAC caveat, and credential revocation reaches in-flight sessions. — see Identity.

Gaps. Sidecar credentials are frozen at pod-create (no mid-execution re-auth); revocation delivery is at-most-once.

ASI04 — Agentic Supply Chain Partial

What OAP does. The MCP tool manifest is content-hash-pinned, with pluggable pinning kinds (mcp / image / cli / skill) under a tiered policy, and drift is enforced, not merely recorded. A tiered allowedMCPServers allowlist bounds what an agent may install. — see Safe tools.

Gaps. No descriptor signing or attestation, and no SBOM/AIBOM — a hash pins content, not origin.

ASI05 — Unexpected Code Execution (RCE) Substantial

What OAP does. Tool pods are hardened: non-root, read-only root filesystem, all capabilities dropped, seccomp RuntimeDefault, no service-account token. Tools execute as argv arrays over pod exec — never a shell, never eval — against a closed set of tools, in per-session sandbox pods. — see Safe tools.

Gaps. Egress is L3/L4 only. Isolation is per session: tool calls within one session share a UID, /proc, /tmp and /work.

ASI06 — Memory & Context Poisoning Partial

What OAP does. Memory is authorized per-subject through SpiceDB — read is session membership, write and delete are the creator's — with tenant/scope isolation and search post-filtered through SpiceDB. External entries are tagged untrusted, and the transcript, authz decisions, and audit kinds are an append-only, Ed25519-signed, tamper-evident log verifiable offline with oap audit verify. — see Memory and Authorization.

Gaps. No content validation on memory writes. Assistant turns are ingested into the knowledge graph without separate validation, so a poisoned turn can influence later recall.

ASI07 — Insecure Inter-Agent Communication Partial

What OAP does. Delegation reaches only a closed, reviewed subagent roster, validated as a DAG, with entries that can be pinned to a bundle digest. The delegation tree is bounded (maxDelegatedAgents, and a per-member mode ceiling), and each subagent is its own scoped, budgeted, audited AgentSession. Parent and child exchange only three typed, separately authorized directions — ask_parent, return_result, and reply_to_subagent — delivered as inspected tool results; free-form agent-to-agent messages were deliberately removed. The sender is authenticated by its own per-session bus subject, and the destination must match a real Channel joining the two sessions. Passing data past its audience parks for the data owner's approval. — see Subagents & delegation and Channels.

Gaps. Delegation stays within one cluster; there is no protocol for agents outside it.

ASI08 — Cascading Failures Partial

What OAP does. Per-session isolation contains blast radius; a silence watchdog, per-phase budgets, and default-on circuit breakers (a per-tool/per-origin three-state machine) stop runaway loops; default-on egress NetworkPolicies bound each session and sandbox; the operator's Secret/ConfigMap reads are code-confined to adopted objects with a fail-loud tripwire. — see Agent definition.

Gaps. The breaker is per-tool/origin, not cross-cutting; the operator's secrets RBAC is cluster-wide by default.

ASI09 — Human-Agent Trust Exploitation Substantial

What OAP does. OAP's whole approval design targets this. External/high-impact actions require explicit confirmation, and the card a human reads is built by an injection-isolated summarizer — a second LLM that sees only the operator-signed schema and arguments, never the primary chat. The mechanically-derived "What" is shown separately from the agent's "Why", a permanent Show-Details escape hatch exposes the raw arguments, and previews are separated from effects (an SVG artifact renders as an inert data: URI, no script). The approver is session-derived and owner-gated at click time. — see Channels and the Authorization guides.

Gaps. No plan-divergence cross-check; no confidence-weighted UI cues.

ASI10 — Rogue Agents Partial

What OAP does. Sessions are disposable and scoped, checked per-action against SpiceDB; the declared tool set is an enforced behavioral manifest — an undeclared tool is structurally uncallable. The audit system is the audit trail: every authorization check writes a tamper-evident, signed decision record that outlives the session. Runtime scope can be narrowed, and both credentials and tools can be revoked into in-flight sessions. — see Authorization and Memory.

Gaps. The tool manifest isn't signed/attested and drift within the allowed surface is undetected; tamper-evidence is not tamper-proofing; there is no self-replication guard.

Mapped to the primitives

Each concept is designed around specific threats:


This page is based on the OWASP Top 10 for Agentic Applications (2026) by the OWASP GenAI Security Project, licensed under CC BY-SA 4.0. The assessment is AuthZed's own and is not affiliated with or endorsed by OWASP.