OWASP Agentic Top 10
Also written ASI01–ASI10
OWASP's first risk taxonomy written specifically for autonomous, tool-using agents: ASI01 Agent Goal Hijack, ASI02 Tool Misuse & Exploitation, ASI03 Identity & Privilege Abuse, ASI04 Agentic Supply-Chain, ASI05 Unexpected Code Execution, ASI06 Memory & Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents. Most of the list lives at the action layer rather than the model layer.
Related terms
-
Tool poisoning
Attack concepts
Hiding instructions in the metadata an agent reads to learn how to use a tool — an MCP server's tool description, its parameter documentation, its schema…
-
Memory / cross-agent propagation
Agents & architecture
A payload that is written in one session and fires in a later one, or in a different agent.
Frameworks & standards
What auditors, buyers and regulators reference. See the compliance crosswalk for the control-by-control mapping.