The OWASP Top 10 for Agentic Applications (2026) covers risks specific to AI agents - systems that use tools, have memory, and can take autonomous actions. ai-blackteam maps agent-specific attacks to these 10 categories.

Running the scorecard

The 10 categories

Attack mappings

ai-blackteam maps its agent exploitation attacks to these categories:

Reading the scorecard

The output follows the same format as the LLM scorecard:
Categories with lower ratings need attention. For agentic systems, ASI01 (Goal Hijack) and ASI06 (Memory Poisoning) are typically the hardest to defend against.