What agentic AI actually is. How it works under the hood. Why the security risk is categorically different from classic LLM chatbots.
Autonomous agents execute.
What stops them from
executing the wrong thing?
The definitive governance handbook for CISOs, CTOs, and risk leaders. From prompt injection to rogue agents — every threat explained, every control mapped.
- 40+
- In-depth pages
- 20
- Mapped threats
- 50
- Audit checklist items
- 100%
- Vendor-neutral
Select your role
Tailored reading paths for each leadership function — jump directly to what matters most for your responsibility area.
OWASP LLM & Agentic Security Risk Matrix
All 20 canonical AI vulnerabilities — categorized by attack domain and severity. Click any entry to read the full breakdown.
Prompt Injection
Crafted inputs hijack model context to override instructions or trigger unintended actions.
Sensitive Info Disclosure
Unsanitized context outputs reveal private PII, credentials, or proprietary system prompts.
Supply Chain Vulnerabilities
Compromised third-party models, plugins, or dataset dependencies.
Data Poisoning
Tampered training or fine-tuning datasets creating malicious backdoors.
Improper Output Handling
Passing raw LLM output into command shells, browsers, or SQL engines.
Excessive Agency
Granting model agents broad privileges or destructive tool access.
System Prompt Leakage
Extracting operational system prompts, business rules, or secret keys.
Vector Weaknesses
Exploiting embedding stores, RAG retrieval context, and vector DBs.
Misinformation & Hallucination
Confidently false outputs causing operational or compliance damage.
Unbounded Consumption
Uncapped API calls leading to resource exhaustion or financial DoS.
Agent Goal Hijack
Attackers manipulate an agent's objectives via malicious prompts, content, or indirect injection.
Tool Misuse & Exploitation
Agents invoke tools or APIs in unintended, destructive, or unauthorized ways.
Identity & Privilege Abuse
Agents inherit or escalate excessive permissions to perform actions outside authorization boundaries.
Agentic Supply Chain
Vulnerabilities introduced through untrusted MCP servers, packages, skills, or model registries.
Unexpected Code Execution
Agents dynamically generate and execute system commands or python scripts without isolation.
Memory & Context Poisoning
Attackers manipulate agent long-term memory or RAG indexes to influence future decision-making.
Insecure Inter-Agent Comm.
Spoofing, interception, or manipulation of messages within multi-agent workflow systems.
Cascading Failures
Small errors in parsing or planning compound iteratively to cause catastrophic system actions.
Human-Agent Trust Exploitation
Attackers manipulate agent outputs to exploit human over-reliance, causing unsafe actions.
Rogue Agents
Compromised or unmanaged agents spawned unauthorized, creating botnets or stealth backdoors.
Full Guide Overview
Where agents are vulnerable. Prompt injection explained plainly. Real incidents that have already happened in the wild.
The official OWASP top 10 vulnerabilities for large language models — every one explained with interactive examples.
The 10 critical risks unique to autonomous agents — from memory poisoning to runaway action loops.
MCP, LiteLLM, NeMo Guardrails, sandboxing — the tools that exist to protect agentic systems, explained for implementers.
NIST AI RMF, EU AI Act, ISO 42001. What you must govern. 50 questions every security leader should be asking today.
Ready to govern autonomous AI in your organization?