OWASP Agentic AI Top 10: Security Risks for Autonomous Agents
A technical explanation of all ten OWASP agentic application risks and the architecture, authorization, testing, and monitoring controls they require.
Cybersecurity content blog
Earlier articles on security engineering, industry standards, product claims, and technical content.
Article archive
Each article addresses a defined search question and links claims to named sources.
A technical explanation of all ten OWASP agentic application risks and the architecture, authorization, testing, and monitoring controls they require.
A practical guide to the OWASP API Security Top 10 2023, with control design, testing priorities, and clear distinctions between its authorization categories.
A technical guide to all ten OWASP Kubernetes risks and the workload, RBAC, secret, network, cloud, admission, and audit controls they require.
A technical guide to all ten OWASP LLM application risks, with practical architecture, testing, authorization, data, and monitoring controls.
A technical guide to the OWASP MCP Top 10 beta, with practical controls for MCP clients, servers, tools, credentials, context, and audit records.
A practical explanation of all ten OWASP mobile application risks and how to test Android, iOS, backend, build, privacy, and binary controls.
A technical guide to all ten OWASP NHI risks and the inventory, ownership, credential, access, lifecycle, and monitoring controls they require.
A current guide to all ten OWASP Top 10 2025 categories, including the new supply chain and exceptional-condition risks.
Agents need enforceable limits on tools, data, and delegated authority. This article maps OAuth, MCP, approvals, revocation, audit, and confused deputy controls.