OWASP Agentic Top 10 (2026)
Use action controls as part of an agent security program.
The OWASP Top 10 for Agentic Applications describes security risks in agentic systems. Authorization controls can address selected execution paths while other defenses remain necessary.
OWASP Top 10 for Agentic Applications for 2026Selected risk themes, not a claim of complete Top 10 coverage. OWASP guidance is not a product certification.
What the evidence can contribute.
Permission Protocol’s suggested mappings below are for review. Confirm the fields available in your integration and whether the artifact is independently signed. Authorization evidence alone does not prove execution, complete coverage, or compliance.
Tool misuse
- Potential receipt or decision evidence
- A tool decision, matched rule, and payload hash for calls routed through the configured gate.
- Your team must establish
- Validate arguments, limit available tools, test enforcement, and cover alternate execution paths.
Identity and privilege abuse
- Potential receipt or decision evidence
- The agent and approver identifiers present in the record.
- Your team must establish
- Authenticate identities, scope credentials, protect secrets, and restrict who can remove or change controls.
Goal manipulation
- Potential receipt or decision evidence
- An approval or denial for the specific action presented to the reviewer.
- Your team must establish
- Defend against prompt injection and misleading context. A gate does not ensure the reviewer understands a malicious request.
Cascading failures
- Potential receipt or decision evidence
- Records of decisions at the connected execution boundaries.
- Your team must establish
- Provide isolation, rate limits, recovery, monitoring, and outage tests. Receipts do not prevent every downstream failure.
Build an evidence pack for one workflow.
Agree the requirement with your reviewer. Collect the configuration, approval records, verification results, exception handling, and tests for the chosen path. Evaluate gaps before expanding.