OWASP Agentic Top 10 Applied to Production Deployments
Real agents with real credentials demand controls that survive when the model's goals get hijacked.
Estelle Haddad
Section
8 stories in Agent Threats.
Real agents with real credentials demand controls that survive when the model's goals get hijacked.
Agents expose attackers to trust boundaries that form at runtime, not design time.
Tool definitions stay mutable after approval, turning runtime trust into a security vulnerability.
Attackers map AI agents' capabilities, memory, and boundaries before exploiting them.
Attackers exploit agentic systems by embedding malicious instructions in content agents retrieve.
Attackers hide commands in files agents must read to work.
Gradual tool chains let agents slip into high-privilege territory undetected.
MCP servers can inject malicious instructions through tool metadata before any tool runs.