Crosswalk
The OWASP Agentic Top 10, against what we actually measure
For each item of the OWASP Top 10 for Agentic Applications for 2026 (ASI01 to ASI10) and of the OWASP MCP Top 10, this page lists which of our checks observe evidence relevant to it, how closely, and where the data is. Items none of our checks reach are marked not measured.
- This is a map of what Council of AI measures against each OWASP item. It is not a compliance claim about anyone, including us.
- OWASP has not reviewed or endorsed this mapping. It is our own editorial work.
- Measuring evidence that bears on an item does not certify anything. A DIRECT or PARTIAL row says what one check observed, on the date and population stated, and nothing about whether any system is safe.
- NOT MEASURED means none of our checks observes evidence for that item. It is a gap in our coverage, not a finding about any system.
Summary
OWASP ASI Top 10 (2026, December 2025):
1 direct · 6 partial · 3 not measured
OWASP MCP Top 10 (beta, IDs suffixed :2025):
1 direct · 4 partial · 5 not measured
These are counts of how many items our checks reach, not a rating of anything. The same numbers, and every row below, are in /crosswalks/owasp-asi.json.
How to read the strength
- Direct
- The check observes, on live systems, a condition the OWASP item names as an instance of the risk. It observes that condition only within the population and date stated.
- Partial
- The check observes something that bears on the item but not the risk condition itself: a precondition, one layer, a declared-versus-served mismatch, or a model's answers to written scenarios about it.
- Not measured
- None of our checks observes evidence for this item.
An item takes the strongest strength among its rows. An item with no rows is NOT_MEASURED. A model-comparison bank counts for an item only when the bank's stated task targets it; a bank that touches the item in one or two questions is noted but not counted.
OWASP ASI Top 10 (2026)
ASI01 Agent Goal Hijack
Not measuredNothing we run injects instructions through content, tools or retrieved data and then watches whether an agent's goal changes. The safety axis measures refusal of direct requests, which is not resistance to goal hijack.
ASI02 Tool Misuse and Exploitation
PartialA tool boundary that accepts an argument the call was not authorised to carry is a precondition for over-scoped tool use. The probe sees the boundary only, not any agent misusing the tool or any backend acting on the argument.
Live data: /api/gspc?axis=effect-binding, /interop/effect-binding-server-probe-2026-09-22.signed.json, /axis/effect-binding
- Conformance axis (MCPBench)Partial
Measures whether models recognise a tool that breaks its declared contract. These are written scenarios, not a deployed agent using tools.
Live data: /api/gspc?axis=conformance
- Cross-reality axis (XRAIV)Partial
Measures whether models ask for confirmation before consequential actions, one of the ways tool misuse happens. These are written scenarios, not a deployed agent.
Live data: /api/gspc?axis=cross-reality
ASI03 Identity and Privilege Abuse
PartialWhether authorisation binds to the request a server executes is part of enforcing least privilege. The probe reaches only servers that answer anonymous callers, so it says nothing about delegated or inherited credentials.
Live data: /api/gspc?axis=effect-binding, /interop/effect-binding-server-probe-2026-09-22.signed.json, /axis/effect-binding
- MCP contract parity: AUTHPartial
A server whose declared authentication disagrees with what its live endpoint requires states its identity requirements inconsistently. That is not an observed privilege escalation.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
Impersonation through unverified agent descriptors is one route to this risk. The census observes which descriptors verify; it does not observe any agent trusting one.
ASI04 Agentic Supply Chain Vulnerabilities
Partial- MCP tool driftPartial
Tool definitions that change after adoption are how a tampered component reaches an agent. The check records change between two observations, never malice, and compares names only where descriptions were not recorded.
Live data: /measurement-capsules/v0.2/tool_drift/record.json
- MCP contract parity: TOOLSPartial
A live tool list that differs from the published one means the component in use is not the one described. A mismatch is not evidence of tampering.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
- MCP contract parity: VERSIONPartial
A version that disagrees across surfaces weakens the provenance of the component. Disagreement is not compromise.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
ASI05 Unexpected Code Execution (RCE)
PartialMeasures how well models used as a guard flag code that spawns a shell or escapes a sandbox. It measures one detection layer on a frozen bank, not whether any agent executes code.
Live data: /api/gspc?axis=jail
ASI06 Memory & Context Poisoning
Not measuredNothing we run writes to an agent's memory or retrieved context and then reads back its later behaviour. The swarm bank has two questions on shared-memory poisoning; under the counting rule that does not make it evidence for this item.
ASI07 Insecure Inter-Agent Communication
DirectThis item names forged agent descriptors and lists signed agent cards as a mitigation. The census fetches live agent cards and verifies each signature against the key the card declares, so an unverifiable descriptor is observed directly. It covers descriptor authenticity only, not message encryption, replay or routing.
A declared protocol version that differs from the one negotiated live is the kind of mismatch that protocol pinning guards against. A mismatch is not a downgrade attack.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
- Swarm axis (SwarmBench v2b)Partial
Model answers to written questions on impersonation and unverifiable claims between agents. These are answers, not observed traffic between agents.
Live data: /api/gspc?axis=swarm
ASI08 Cascading Failures
Partial- Swarm axis (SwarmBench v2b)Partial
Includes questions on injected instructions spreading between agents, supervisors that fail open and agents spawning agents without limit. These are model answers on a frozen bank; no system is run until it fails.
Live data: /api/gspc?axis=swarm
ASI09 Human-Agent Trust Exploitation
Partial- Affect axis (AffectBench)Partial
Measures model responses where a person could be manipulated or exposed. It does not observe whether people over-trust a deployed agent.
Live data: /api/gspc?axis=affect
ASI10 Rogue Agents
Not measuredNothing we run watches an agent over time for behaviour that departs from its purpose without an attacker. The jail bank classifies code cells; it does not observe an agent.
OWASP MCP Top 10 (beta)
Beta. The project road map says it is in Phase 3, 'Beta Release and Pilot Testing', with the next release planned for October 2026.
MCP01:2025 Token Mismanagement & Secret Exposure
Not measuredWe do not scan servers, logs or model memory for exposed secrets or token lifetimes.
MCP02:2025 Privilege Escalation via Scope Creep
PartialA boundary that does not refuse an unauthorised argument is weak scope enforcement at one point in time. Scope creep is change over time, which this single run does not observe.
Live data: /api/gspc?axis=effect-binding, /interop/effect-binding-server-probe-2026-09-22.signed.json, /axis/effect-binding
- MCP tool driftPartial
A tool set that grows between two observations is how scope creeps. The check records change at name granularity and does not judge the privileges a new tool carries.
Live data: /measurement-capsules/v0.2/tool_drift/record.json
MCP03:2025 Tool Poisoning
Partial- MCP tool driftPartial
Records whether advertised tools changed between two observations. A change is not poisoning, and unchanged names do not rule it out.
Live data: /measurement-capsules/v0.2/tool_drift/record.json
- MCP contract parity: TOOLSPartial
Records whether the live tool list matches what the server publishes elsewhere. It does not read tool descriptions for injected instructions.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
- Conformance axis (MCPBench)Partial
Measures whether models recognise tools that act outside their declared contract, on written scenarios.
Live data: /api/gspc?axis=conformance
MCP04:2025 Software Supply Chain Attacks & Dependency Tampering
Partial- MCP contract parity: VERSIONPartial
Records version disagreement between a server's published surfaces and its live endpoint. It does not inspect dependencies.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP05:2025 Command Injection & Execution
PartialMeasures how well models used as a guard flag code that executes shell commands. It does not test any server for injection.
Live data: /api/gspc?axis=jail
MCP06:2025 Intent Flow Subversion
Not measuredNothing we run plants instructions in retrieved context and watches whether an agent's intent changes.
MCP07:2025 Insufficient Authentication & Authorization
DirectThis item is servers failing to enforce access control during interactions. The probe calls live servers with an argument the call was not authorised to carry and records whether the boundary refuses it, so a boundary that accepts it is that condition observed. Only servers that answer anonymous callers are probed, and backend use of the argument is not observed.
Live data: /api/gspc?axis=effect-binding, /interop/effect-binding-server-probe-2026-09-22.signed.json, /axis/effect-binding
- MCP contract parity: AUTHPartial
Records whether a server's declared authentication agrees with what its live endpoint requires. A disagreement is inconsistent disclosure, not a bypass.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP08:2025 Lack of Audit and Telemetry
Not measuredWe do not observe the logs or telemetry any server keeps.
MCP09:2025 Shadow MCP Servers
Not measuredShadow servers are, by definition, outside the public registries our census reads.
MCP10:2025 Context Injection & Over-Sharing
Not measuredNothing we run shares context across sessions, users or agents and looks for leakage.
The checks
Counts shown beside each census check are read by the generator from the committed record files named in the JSON, with their as_of. GSPC axes carry no count here; follow the live link.
Effect binding (server probe)
Calls a read-only tool on live third-party MCP servers with one extra argument the call was not authorised to carry, and records whether the server's boundary refuses it. It sees the boundary, not whether any backend used the argument. Servers that demand credentials are recorded as uncheckable and never probed.
Recorded 2026-09-22: 261 tool-call servers probed with a verdict, of 600 tried — BINDS 0 · PARTIAL 23 · DOES NOT BIND 238. Read from /interop/effect-binding-server-probe-2026-09-22.json.
Live data: /api/gspc?axis=effect-binding, /interop/effect-binding-server-probe-2026-09-22.signed.json, /axis/effect-binding
MCP contract parity: TOOLS
For each MCP endpoint where two or more public surfaces (registry entry, mcp.json, server card, x402 manifest, live tools/list) state its tools, whether they agree. INCONSISTENT means two public statements disagree, not which one is true.
Recorded 2026-09-26: 1129 endpoint capsules — CONSISTENT 908 · INCONSISTENT 219 · UNCHECKABLE 2. Read from /measurement-capsules/v0.2/contract_parity/record.json.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP contract parity: VERSION
Whether the server version stated on each public surface agrees with the version the live endpoint reports.
Recorded 2026-09-26: 5807 endpoint capsules — CONSISTENT 3163 · INCONSISTENT 2644. Read from /measurement-capsules/v0.2/contract_parity/record.json.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP contract parity: PROTOCOL
Whether the MCP protocol version a server declares agrees with the version it negotiates on a live initialize call.
Recorded 2026-09-26: 739 endpoint capsules — CONSISTENT 459 · INCONSISTENT 33 · UNCHECKABLE 247. Read from /measurement-capsules/v0.2/contract_parity/record.json.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP contract parity: AUTH
Whether the authentication a server declares on its public surfaces agrees with what its live endpoint requires.
Recorded 2026-09-26: 1357 endpoint capsules — CONSISTENT 928 · INCONSISTENT 5 · UNCHECKABLE 424. Read from /measurement-capsules/v0.2/contract_parity/record.json.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
MCP contract parity: PAYMENT
Whether the payment terms a server declares on its public surfaces agree with each other and with its live payment challenge.
Recorded 2026-09-26: 116 endpoint capsules — CONSISTENT 112 · INCONSISTENT 4. Read from /measurement-capsules/v0.2/contract_parity/record.json.
Live data: /measurement-capsules/v0.2/contract_parity/record.json, /evidence/mcp-contract-parity/
A2A agent-card signature verification
Fetches the agent cards listed in a public A2A registry and, for each card that carries a signature, verifies it against the key the card declares, under the card's declared protocol version. Cards served without a signature are counted but not verified.
Recorded 2026-09-26: 33 signed agent cards — FAILED 8 · UNCHECKABLE 12 · VERIFIED 13 · 389 further cards served unsigned. Read from /measurement-capsules/v0.2/a2a_card/record.json.
MCP tool drift
For each MCP endpoint observed at two independent times, whether the tools it advertised are the same. It compares names, and descriptions and input schemas where both observations recorded them. A change is a recorded difference, never a finding of malice.
Recorded 2026-09-26: 3240 MCP endpoints — UNCHANGED AT NAME GRANULARITY 1485 · UNCHECKABLE 1755. Read from /measurement-capsules/v0.2/tool_drift/record.json.
Live data: /measurement-capsules/v0.2/tool_drift/record.json
x402 door conformance
Whether the x402 payment challenge each of our own published payment doors returns has the documented shape. It is a check of our own endpoints, and it is not proof of delivery or settlement.
Recorded 2026-09-14: 11 own payment doors — PROBED CONFORMANT 11 · MISMATCH 0 · UNCHECKABLE 0. Read from /interop/x402-door-conformance-2026-09/card-x402-door-conformance-summary-unsigned.json.
Live data: /interop/x402-door-conformance-2026-09/report.json, /interop/x402-door-conformance-2026-09/card-x402-door-conformance-summary-unsigned.json
Conformance axis (MCPBench)
A fleet of models reads written descriptions of MCP tools and judges whether each one breaks its declared contract, for example a tool annotated read-only that deletes files. Graded against fixed labels on a frozen bank.
Live data: /api/gspc?axis=conformance
Cross-reality axis (XRAIV)
A fleet of models decides whether an autonomous agent should proceed, ask for confirmation or refuse before an action, such as overwriting a file it did not create. Graded against fixed labels on a frozen bank.
Live data: /api/gspc?axis=cross-reality
Jail axis (GoldBank-Detector)
A fleet of models, used as a guard, classifies code cells as sandbox-escape attempts (for example spawning a shell) or benign. Graded against a frozen gold bank.
Live data: /api/gspc?axis=jail
Swarm axis (SwarmBench v2b)
A fleet of models answers written questions on multi-agent coordination safety, such as injected instructions spreading between agents or a worker impersonating an orchestrator. Answers are keyword-graded on a frozen bank.
Live data: /api/gspc?axis=swarm
Affect axis (AffectBench)
A fleet of models responds to scenarios involving manipulation of, disclosure to and vulnerability of a human user. Graded against fixed labels on a frozen bank.
Live data: /api/gspc?axis=affect
The census checks are published as signed measurement capsules, one adapter per kind; see measurement capsules.
contract_parity: carries MCP contract parity: TOOLS; MCP contract parity: VERSION; MCP contract parity: PROTOCOL; MCP contract parity: AUTH; MCP contract parity: PAYMENT (record)a2a_card: carries A2A agent-card signature verification (record)tool_drift: carries MCP tool drift (record)cross_ledger: Tokenised-asset supply across ledgers; bears on no item. (record)mill_cross_runtime: Whether a model's measured result reproduces on a second runtime; bears on no item. (record)public_signals: Outside signals about CSOAI itself; bears on no item. (record)self_parity: What outside indexes say about our own offerings; bears on no item. (record)
What we measure that maps to neither list
- MCP contract parity: PAYMENT: Payment-term consistency bears on no item in either list.
- x402 door conformance: It checks the shape of our own payment challenges, which bears on no item in either list.
- governance axis: EU AI Act risk-tier classification; no agentic threat surface. (live)
- safety axis: Refusal of direct requests. No injected or indirect instruction is present, so it is not evidence about goal hijack. (live)
- provenance axis: Survival of synthetic-content marking; not an agentic risk in either list. (live)
- continuity axis: Post-quantum status of cryptographic assumptions; not an agentic risk in either list. (live)
- openness axis: Licence reasoning against intended use; not an agentic risk in either list. (live)
- machinery-conformity axis: Classification under the EU Machinery Regulation; not an agentic risk in either list. (live)
- care axis: Harm-avoidance trade-offs in paired conduct scenarios; bears on no single item closely enough to state. (live)
- detector-interop axis: Cross-detector watermark interoperability; not an agentic risk in either list. (live)
- art5-safeguard axis: Whether models refuse to build practices the EU AI Act prohibits, such as subliminal manipulation. That is refusal to build a manipulative system, not an agent exploiting a person's trust, so it is not counted for ASI09. (live)
- provenance-controls axis: On-chain issuer control facts for tokenised assets; not an agentic risk. (live)
- reserve-attestation axis: Issuer reserve-attestation disclosure; not an agentic risk. (live)
- regulatory-framework axis: Whether an issuer's governing regime is declared; not an agentic risk. (live)
- distribution-integrity axis: Token supply and holder facts; not an agentic risk. (live)
- custody-disclosure axis: Whether a custodian and auditor are named; not an agentic risk. (live)
- ai-adoption-components axis: Cited public statistics; not a measurement of any system. (live)
- labour-components axis: Cited public statistics; not a measurement of any system. (live)
- humanoid-labour-index axis: Vendor deployment disclosures; not an agentic risk. (live)
Sources and licences
OWASP Top 10 for Agentic Applications for 2026, OWASP GenAI Security Project, Agentic Security Initiative. Version 2026, December 2025, published 2025-12-09. Released.
Links: resource page, announcement, PDF (SHA-256 a2db94cd00b08e0b3a5e5b619afe024bdbcd74503111085705e4f3dd886fcb5c). Read on 2026-09-27.
ASI IDs and titles are reproduced unchanged from the OWASP Top 10 for Agentic Applications for 2026, OWASP GenAI Security Project, licensed CC BY-SA 4.0. No OWASP description text is reproduced or adapted; the rationale text is ours. Licence: CC BY-SA 4.0.
OWASP MCP Top 10, OWASP MCP Top 10 project (OWASP Foundation). Version 2025 (item IDs carry the suffix :2025). Beta. The project road map says it is in Phase 3, 'Beta Release and Pilot Testing', with the next release planned for October 2026..
Links: project, list at commit 22aff0d08e10. Read on 2026-09-27.
MCP IDs and titles are reproduced unchanged from the OWASP MCP Top 10 (beta), licensed CC BY-NC-SA 4.0. No OWASP description text is reproduced or adapted. This page is free to read and is not sold. Licence: CC BY-NC-SA 4.0. The project page links CC BY-NC-SA 4.0 and, in the same sentence, calls it the Attribution-ShareAlike licence. We follow the linked licence, which is the stricter one.
Our mapping, strengths and rationale are published under CC BY-SA 4.0. OWASP is a trademark of the OWASP Foundation; its use here identifies the source lists and implies no affiliation.
Other OWASP pages on this site
- /owasp-agentic/: Maps ASI01 to ASI10 to the practices we apply to our own signing, keys and publishing. It describes our own controls, not measurements of other systems, and it predates the census checks used here.
- /owasp-asi/: Despite its address, maps our axes to the OWASP AI Exchange, a different OWASP document. It does not use the ASI list.
measurement/owasp-asi/asi-gspc-axis-map.json: An internal axis-only map from 14 September 2026 with no strength grades. It relates jail to ASI10, cross-reality to ASI03 and art5-safeguard to ASI09; this crosswalk does not count those, for the reasons given on each check or in the unmapped list.
Edited 2026-09-27. Generated from scripts/crosswalks/owasp-asi.source.json (SHA-256 07ad1bb81b143e92…). Think a row is wrong? Email nicholas@csoai.org; changes are recorded in the corrections ledger. See also methodology.