OWASP LLM Top 10
OWASP's list of the ten most critical risks in applications built on large language models — LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM06 Excessive Agency and the rest. It is the vocabulary most security teams already share, so it is usually where an agent-security conversation starts even though it was written for LLM applications generally rather than for tool-using agents specifically.
See also OWASP Agentic Top 10 · our LLM Top 10 mapping
Related terms
-
OWASP Agentic Top 10
Frameworks & standards
OWASP's first risk taxonomy written specifically for autonomous, tool-using agents: ASI01 Agent Goal Hijack, ASI02 Tool Misuse & Exploitation, ASI03…
Frameworks & standards
What auditors, buyers and regulators reference. See the compliance crosswalk for the control-by-control mapping.