The OWASP agentic threats, in plain language
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
OWASP's agentic threat model names fifteen-plus ways an agent gets turned against you. Most map onto pages you have already read; this is that map.
The LLM Top 10 is a ranked list of risks for any LLM application. The agentic threat model is a different document for a narrower thing: systems where the model does not just answer but acts: it holds tools, memory, identity, and other agents to talk to. It is "the first in a series of guides from the OWASP Agentic Security Initiative", and it is a taxonomy rather than a top ten: the version here names threats T1 through T17.
The point of reading it against this site is that the agentic threats are not new physics. They are the failure modes the security and trust tracks already describe, sorted by the part of an agent they attack. Below, each in plain language, pointed at where the depth lives.
Attacks on what the agent knows
T1: Memory Poisoning
"Memory Poisoning involves exploiting an AI's memory systems, both short and long-term, to introduce malicious or false data and exploit the agent's context". The persistent-memory version of prompt injection: a bad instruction written into memory outlives the conversation that planted it.
T5: Cascading Hallucination Attacks
"These attacks exploit an AI's tendency to generate contextually plausible but false information", which then propagates. This is why it invents things turned into an attack: one confident error becomes an input the next step trusts, so verifying what you cannot judge is the containment.
Attacks on what the agent can do
T2: Tool Misuse
"Tool Misuse occurs when attackers manipulate AI agents to abuse their integrated tools through deceptive prompts or commands, operating within authorized permissions". Note the last clause: the agent stays inside its grants and still does harm. That is the whole tool-use footguns argument, and the reason blast radius is about scoping the grant, not trusting the intent.
T3: Privilege Compromise
"Privilege Compromise arises when attackers exploit weaknesses in permission management to perform unauthorized actions". The case for narrow permissions and least privilege.
T11: Unexpected RCE and Code Attacks
Model-generated code or an execution environment gets turned into a way to run attacker code. The reason running unattended and sandboxing are not optional once an agent can execute.
T4: Resource Overload
Exhausting an agent's compute, memory, or service budget to degrade or break it. The adversarial cousin of ordinary quota discipline.
Attacks on the agent's goals and honesty
T6: Intent Breaking & Goal Manipulation
Redirecting an agent's objectives and reasoning. The attack that makes writing a goal a security control as much as a productivity tip.
T7: Misaligned & Deceptive Behaviors
An agent taking harmful or disallowed actions to fulfil what it thinks the objective is. The reason reviewing the output means checking the work, not the agent's account of it.
Attacks that use the humans
T10: Overwhelming Human in the Loop
"This threat targets systems with human oversight and decision validation, aiming to exploit human cognitive limitations": flooding the approver until they rubber-stamp. This is automation bias weaponised: the defence of "a human approves it" fails when the human is drowned.
T15: Human Manipulation
The agent's own trustworthiness is the attack surface: "the trust relationship reduces user skepticism, increasing reliance on the agent's responses and autonomy". The clean statement of why deskilling and misplaced trust are security problems as well as quality ones.
Attacks on accountability and identity
T8: Repudiation & Untraceability
"Occurs when actions performed by AI agents cannot be traced back or accounted for due to insufficient logging". Exactly the gap incident response tells you to close before the incident, and what the step trail exists to prevent.
T9: Identity Spoofing & Impersonation
Abusing authentication to act as an agent or user under a false identity. The identity face of the confused deputy.
Attacks between agents
The multi-agent threats (T12 to T14, and T16) are where the model goes beyond this site's current depth, and worth naming for exactly that reason.
T12 — Agent Communication Poisoning manipulates the channel between agents to spread false information. T13 — Rogue Agents are compromised agents operating outside monitoring. T14 — Human Attacks on Multi-Agent Systems exploit the trust and delegation between agents to escalate. T16 — Insecure Inter-Agent Protocol Abuse targets "flaws in protocols like MCP or A2A, such as consent bypass or context hijacking": the protocol-level confused deputy, and the reason building an MCP server carries a trust-boundary warning.
The through-line: every trust assumption you make about one agent multiplies across a system of them, and the aggregation is the vulnerability.
The one that reaches back to the supply chain
T17: Supply Chain Compromise
A poisoned component (a skill, an MCP server, a plugin) ships inside the agent and turns its actions against you. The reason vetting what you install is a recurring theme here rather than a one-time check.
What goes wrong
Reading it as fifteen new problems. Most are old failure modes wearing an agentic label. Recognising T2 as tool-use footguns or T10 as automation bias tells you the mitigation is already on this site.
Treating it as a checklist to pass. It is a threat model to reason with. The value is asking, for your agent, which of these its design actually exposes.
Ignoring the multi-agent half because you run one agent. T16 and T17 reach a single agent the moment it talks to a tool or a server someone else wrote, which is most agents.
Citing the wrong edition. This is the v1.0 taxonomy. If an auditor references a later version, read their copy; editions of these lists move.
How to check it worked
Take one real agent you run and walk the list once, marking each threat "exposed" or "not applicable" with a one-line reason. The exposed rows are your actual threat model, and each should point at a control you can name — a scope, a log, a review step. A row you cannot map to a control is the gap the taxonomy just found for you.
Sources
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.