OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations)
OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations) — 41% of in-scope requirements covered.
8 requirements · 8 in scope (5 designed · 3 advisory). The 41% is weighted over the in-scope base.
Source: OWASP Gen-AI Security Project — Agentic AI Threats & Mitigations / Top 10 for Agentic Applications (2025), as crosswalked by AIUC-1. The threat classes are agent-action attack surfaces (memory poisoning, tool misuse, privilege compromise, intent/goal manipulation, deceptive behaviour, repudiation, identity spoofing, human-in-the-loop overwhelm). KYE Protocol™ governs the AUTHORITY, EVIDENCE and FINALITY of the agent action each threat targets — it is the runtime enforcement + replay-evidence substrate, not an agent scanner or red-team tool. Starter requirement set; deepen by graft through the §70 rail. · License: OWASP materials are published under Creative Commons; KYE™ registry paraphrases each threat's intent and cites the threat identifier for mapping purposes only.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Action authority | 3 | 0 | 1 | 2 | 0 | 33% |
| Identity & accountability | 3 | 0 | 2 | 1 | 0 | 42% |
| Memory & oversight | 2 | 0 | 2 | 0 | 0 | 50% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
owasp-agentic.t2-tool-misuse |
T2 Tool Misuse — agent invokes a tool outside its authorised scope | advisory | constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/52-DELEGATED-AGENT-BINDING.mdaudit_events: kye.evidence.decision_map.v1 |
owasp-agentic.t3-privilege-compromise |
T3 Privilege Compromise — agent escalates or inherits excess authority | designed | constitution_refs: constitution/12-PURPOSE-PERMISSION.md |
owasp-agentic.t6-intent-goal-manipulation |
T6 Intent Breaking & Goal Manipulation — action diverges from granted purpose | advisory | constitution_refs: constitution/12-PURPOSE-PERMISSION.mdaudit_events: kye.evidence.decision_map.v1 |
owasp-agentic.t8-repudiation-untraceability |
T8 Repudiation & Untraceability — no provable record of who/what acted | advisory | constitution_refs: constitution/13-RESILIENCE-LOOP.mdaudit_events: kye.evidence.pack.v1, kye.replay.proof.v1, kye.evidence.decision_map.v1 |
owasp-agentic.t9-identity-spoofing |
T9 Identity Spoofing & Impersonation — agent identity is not first-class | designed | constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md |
owasp-agentic.t7-misaligned-deceptive |
T7 Misaligned & Deceptive Behaviours — contestable, reviewable outcomes | designed | constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md |
owasp-agentic.t1-memory-poisoning |
T1 Memory Poisoning — agent memory used as authority-bearing state | designed | constitution_refs: constitution/63-MEMORY-AUTHORITY-RAIL.md |
owasp-agentic.t10-hitl-overwhelm |
T10 Overwhelming Human-in-the-Loop — approval fatigue defeats oversight | designed | constitution_refs: constitution/36-GOVERNEDUI.md |