RISKS / ASI01–ASI10
Top 10 for Agentic Risks 2026
Ordered from most critical to least. ASI01 is the highest-impact risk in the OWASP Top 10 for Agentic Applications 2026. ASI10 is the last entry in that list, not a minor issue.
Each line below is a short independent summary for holders of agentic NFTs. It is not the OWASP text, and it is not an OWASP endorsement of this console. The PDF in the vault is the unmodified document.
| ASI ID | Name | Brief description |
|---|---|---|
| ASI01 | Agent Goal Hijack | An attacker tricks the agent into changing its main goal or following new, hidden instructions. |
| ASI02 | Tool Misuse & Exploitation | An agent applies a legitimate tool in an unsafe or unintended way, leading to data exfiltration or workflow hijacking. |
| ASI03 | Identity & Privilege Abuse | An agent borrows too much power or uses old credentials to perform actions it should not be allowed to do. |
| ASI04 | Agentic Supply Chain Vulnerabilities | Risks from third-party agents, tools, or prompt templates that may be malicious or tampered with at runtime. |
| ASI05 | Unexpected Code Execution (RCE) | The agent generates and runs a command that lets an attacker take over the server or system. |
| ASI06 | Memory & Context Poisoning | Bad data is planted in the agent’s memory, so later decisions are biased or unsafe. |
| ASI07 | Insecure Inter-Agent Communication | Exchanges between agents that lack authentication or integrity, allowing spoofing or message interception. |
| ASI08 | Cascading Failures | A single fault propagates and amplifies across autonomous agent networks, with system-wide impact. |
| ASI09 | Human-Agent Trust Exploitation | The persuasive, human-like manner of an agent is used to push a person into an unsafe action. |
| ASI10 | Rogue Agents | A compromised agent leaves its intended scope and acts harmfully, or pursues a hidden goal. |
What this changes for a holder
Goal hijack is the instruction question. Tool misuse and privilege abuse are the access question. Memory poisoning is what the agent may remember. Spoofed agent messages are not approval. A rogue agent is the case for a stop control and a record of what was proposed, attempted, and completed.
Credit
OWASP Top 10 for Agentic Applications 2026. OWASP GenAI Security Project — Agentic Security Initiative. Version 2026, December 2025. genai.owasp.org. Licensed CC BY-SA 4.0. The one-line descriptions on this page were shortened. The downloadable PDF was not changed. OWASP does not endorse this site.