OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations) · v2025

OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations)

OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations) — 41% of in-scope requirements covered.

8 requirements · 8 in scope (5 designed · 3 advisory). The 41% is weighted over the in-scope base.

Source: OWASP Gen-AI Security Project — Agentic AI Threats & Mitigations / Top 10 for Agentic Applications (2025), as crosswalked by AIUC-1. The threat classes are agent-action attack surfaces (memory poisoning, tool misuse, privilege compromise, intent/goal manipulation, deceptive behaviour, repudiation, identity spoofing, human-in-the-loop overwhelm). KYE Protocol governs the AUTHORITY, EVIDENCE and FINALITY of the agent action each threat targets — it is the runtime enforcement + replay-evidence substrate, not an agent scanner or red-team tool. Starter requirement set; deepen by graft through the §70 rail. · License: OWASP materials are published under Creative Commons; KYE registry paraphrases each threat's intent and cites the threat identifier for mapping purposes only.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Action authority 3 0 1 2 0 33%
Identity & accountability 3 0 2 1 0 42%
Memory & oversight 2 0 2 0 0 50%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
owasp-agentic.t2-tool-misuse T2 Tool Misuse — agent invokes a tool outside its authorised scope advisory constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/52-DELEGATED-AGENT-BINDING.md
audit_events: kye.evidence.decision_map.v1
owasp-agentic.t3-privilege-compromise T3 Privilege Compromise — agent escalates or inherits excess authority designed constitution_refs: constitution/12-PURPOSE-PERMISSION.md
owasp-agentic.t6-intent-goal-manipulation T6 Intent Breaking & Goal Manipulation — action diverges from granted purpose advisory constitution_refs: constitution/12-PURPOSE-PERMISSION.md
audit_events: kye.evidence.decision_map.v1
owasp-agentic.t8-repudiation-untraceability T8 Repudiation & Untraceability — no provable record of who/what acted advisory constitution_refs: constitution/13-RESILIENCE-LOOP.md
audit_events: kye.evidence.pack.v1, kye.replay.proof.v1, kye.evidence.decision_map.v1
owasp-agentic.t9-identity-spoofing T9 Identity Spoofing & Impersonation — agent identity is not first-class designed constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
owasp-agentic.t7-misaligned-deceptive T7 Misaligned & Deceptive Behaviours — contestable, reviewable outcomes designed constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
owasp-agentic.t1-memory-poisoning T1 Memory Poisoning — agent memory used as authority-bearing state designed constitution_refs: constitution/63-MEMORY-AUTHORITY-RAIL.md
owasp-agentic.t10-hitl-overwhelm T10 Overwhelming Human-in-the-Loop — approval fatigue defeats oversight designed constitution_refs: constitution/36-GOVERNEDUI.md