OWASP Agentic Top 10 — coverage
A map of how OAP addresses the OWASP Top 10 for Agentic Applications (2026). Each concept in these docs is designed around specific threats below; each threat here names the OAP mechanism that answers it and the gaps that remain. This is an advisory assessment, not a certification — coverage is a qualitative judgement, and honest about what's missing.
Across the ten: 4 substantially addressed · 6 partial.
ASI01 — Agent Goal Hijack Partial
What OAP does. Tool output cannot widen what the agent may do: every resulting action is checked outside the model, and high-impact and external actions can be human-approval-gated. Tool results are the only non-user ingress path; as a secondary aid, each is wrapped in an unpredictable per-result nonce and the system prompt's spotlighting rule tells the model to treat delimited content as data, never instructions. A pluggable content-guard seam inspects tool I/O, and two inspectors ship: a prompt-injection classifier (run in a zero-egress pod) and a URL allowlist. — see Safe tools, Content guards & egress, and Agent definition.
Gaps. No goal-lock or plan-divergence detection; inspection covers tool I/O, not the agent's own replies.
ASI02 — Tool Misuse & Exploitation Substantial
What OAP does. This is OAP's home turf. Tools are dual-validated — at authoring time and again at
execution time — behind deny-by-default subcommand/field allowlists and CEL, and they run as argv arrays,
never through a shell. Each tool's stateImpact (readonly / readwrite / external) drives the authorization
check and whether a human is asked; every action is checked per-action against SpiceDB. Secrets are scrubbed
from output; default-on circuit breakers, plus opt-in per-tool rate limits and per-call data-volume budgets,
bound runaway use. — see
Safe tools.
Gaps. Egress control is L3/L4 only; the volume budget is per-call, not cumulative.
ASI03 — Identity & Privilege Abuse Substantial
What OAP does. Each agent has its own AgentIdentity — there is no shared credential catalog. Acting on a
user's behalf goes through UserIdentity → SessionUserIdentity with the credential set narrowed to what the
session's agent asked for, and a token broker resolves credentials just-in-time (a valet key, fail-closed).
Critically, an agent never acts on authority of its own: checks run against the user it acts for, or, for a
session with no user, a principal of its own (the session itself, or a service it declares) with no standing grants — which structurally blocks the
confused-deputy problem; grants are bound to an arguments-hash HMAC caveat, and credential revocation reaches in-flight
sessions. — see Identity.
Gaps. Sidecar credentials are frozen at pod-create (no mid-execution re-auth); revocation delivery is at-most-once.
ASI04 — Agentic Supply Chain Partial
What OAP does. The MCP tool manifest is content-hash-pinned, with pluggable pinning kinds (mcp / image /
cli / skill) under a tiered policy, and drift is enforced, not merely recorded. A tiered allowedMCPServers
allowlist bounds what an agent may install. — see Safe tools.
Gaps. No descriptor signing or attestation, and no SBOM/AIBOM — a hash pins content, not origin.
ASI05 — Unexpected Code Execution (RCE) Substantial
What OAP does. Tool pods are hardened: non-root, read-only root filesystem, all capabilities dropped,
seccomp RuntimeDefault, no service-account token. Tools execute as argv arrays over pod exec — never a
shell, never eval — against a closed set of tools, in per-session sandbox pods. — see
Safe tools.
Gaps. Egress is L3/L4 only. Isolation is per session: tool calls within one session share a UID, /proc, /tmp and /work.
ASI06 — Memory & Context Poisoning Partial
What OAP does. Memory is authorized per-subject through SpiceDB — read is session membership, write and
delete are the creator's — with tenant/scope isolation and search post-filtered through SpiceDB. External
entries are tagged untrusted, and the transcript, authz decisions, and audit kinds are an append-only,
Ed25519-signed, tamper-evident log verifiable offline with oap audit verify. — see Memory and
Authorization.
Gaps. No content validation on memory writes. Assistant turns are ingested into the knowledge graph without separate validation, so a poisoned turn can influence later recall.
ASI07 — Insecure Inter-Agent Communication Partial
What OAP does. Delegation reaches only a closed, reviewed subagent roster, validated as a DAG, with
entries that can be pinned to a bundle digest. The delegation tree is bounded (maxDelegatedAgents, and a
per-member mode ceiling), and each subagent is its own scoped, budgeted, audited AgentSession. Parent and child
exchange only three typed, separately authorized directions — ask_parent, return_result, and
reply_to_subagent — delivered as inspected tool results; free-form agent-to-agent messages were deliberately
removed. The sender is authenticated by its own per-session bus subject, and the destination must match a real
Channel joining the two sessions. Passing data past its audience parks for the data owner's approval. — see
Subagents & delegation and Channels.
Gaps. Delegation stays within one cluster; there is no protocol for agents outside it.
ASI08 — Cascading Failures Partial
What OAP does. Per-session isolation contains blast radius; a silence watchdog, per-phase budgets, and default-on circuit breakers (a per-tool/per-origin three-state machine) stop runaway loops; default-on egress NetworkPolicies bound each session and sandbox; the operator's Secret/ConfigMap reads are code-confined to adopted objects with a fail-loud tripwire. — see Agent definition.
Gaps. The breaker is per-tool/origin, not cross-cutting; the operator's secrets RBAC is cluster-wide by
default.
ASI09 — Human-Agent Trust Exploitation Substantial
What OAP does. OAP's whole approval design targets this. External/high-impact actions require explicit
confirmation, and the card a human reads is built by an injection-isolated summarizer — a second LLM that
sees only the operator-signed schema and arguments, never the primary chat. The mechanically-derived "What" is
shown separately from the agent's "Why", a permanent Show-Details escape hatch exposes the raw arguments, and
previews are separated from effects (an SVG artifact renders as an inert data: URI, no script). The approver
is session-derived and owner-gated at click time. — see Channels and the
Authorization guides.
Gaps. No plan-divergence cross-check; no confidence-weighted UI cues.
ASI10 — Rogue Agents Partial
What OAP does. Sessions are disposable and scoped, checked per-action against SpiceDB; the declared tool set is an enforced behavioral manifest — an undeclared tool is structurally uncallable. The audit system is the audit trail: every authorization check writes a tamper-evident, signed decision record that outlives the session. Runtime scope can be narrowed, and both credentials and tools can be revoked into in-flight sessions. — see Authorization and Memory.
Gaps. The tool manifest isn't signed/attested and drift within the allowed surface is undetected; tamper-evidence is not tamper-proofing; there is no self-replication guard.
Mapped to the primitives
Each concept is designed around specific threats:
- Safe tools → ASI02, ASI04, ASI05, ASI01
- Identity & credentials → ASI03
- Authorization → ASI02, ASI03, ASI06, ASI10
- Agent definition → ASI01, ASI07, ASI08, ASI09
- Channels & continuity → ASI07, ASI09
- Memory & knowledge → ASI06, ASI10
This page is based on the OWASP Top 10 for Agentic Applications (2026) by the OWASP GenAI Security Project, licensed under CC BY-SA 4.0. The assessment is AuthZed's own and is not affiliated with or endorsed by OWASP.