ai-blackteam maps its 1,020 curated attacks to both the OWASP Top 10 for LLM Applications (2026) and the OWASP Top 10 for Agentic Applications (2026), so you can test a model against the standard and get a category-by-category scorecard.

Run the scorecard

What it covers

The OWASP LLM Top 10 (2026) categories are prompt injection (LLM01), sensitive information disclosure (LLM02), excessive agency (LLM03), supply chain (LLM04), data and model poisoning (LLM05), unbounded consumption (LLM06), misinformation (LLM07), hidden context exposure (LLM08), vector and embedding weaknesses (LLM09), and improper output handling (LLM10). The OWASP Agentic Top 10 (2026) adds the action layer: ASI01 Agent Goal Hijack, ASI02 Tool Misuse & Exploitation, ASI03 Identity & Privilege Abuse, ASI04 Agentic Supply Chain Compromise, ASI05 Unexpected Code Execution, ASI06 Memory & Context Poisoning, and more. ai-blackteam maps all 39 of its tool-use attacks to these categories.

Export for compliance

Why this matters

The 2026 secure baseline for AI applications layers three OWASP frameworks: the web Top 10, the LLM Top 10 (2026), and the Agentic Top 10 (2026). ai-blackteam covers the model and agent layers and produces audit-ready scorecards for both. See also: OWASP LLM Top 10 and OWASP Agentic Top 10.