Crosswalk

The OWASP Agentic Top 10, against what we actually measure

For each item of the OWASP Top 10 for Agentic Applications for 2026 (ASI01 to ASI10) and of the OWASP MCP Top 10, this page lists which of our checks observe evidence relevant to it, how closely, and where the data is. Items none of our checks reach are marked not measured.

  • This is a map of what Council of AI measures against each OWASP item. It is not a compliance claim about anyone, including us.
  • OWASP has not reviewed or endorsed this mapping. It is our own editorial work.
  • Measuring evidence that bears on an item does not certify anything. A DIRECT or PARTIAL row says what one check observed, on the date and population stated, and nothing about whether any system is safe.
  • NOT MEASURED means none of our checks observes evidence for that item. It is a gap in our coverage, not a finding about any system.

Summary

OWASP ASI Top 10 (2026, December 2025):

1 direct · 6 partial · 3 not measured

OWASP MCP Top 10 (beta, IDs suffixed :2025):

1 direct · 4 partial · 5 not measured

These are counts of how many items our checks reach, not a rating of anything. The same numbers, and every row below, are in /crosswalks/owasp-asi.json.

How to read the strength

Direct
The check observes, on live systems, a condition the OWASP item names as an instance of the risk. It observes that condition only within the population and date stated.
Partial
The check observes something that bears on the item but not the risk condition itself: a precondition, one layer, a declared-versus-served mismatch, or a model's answers to written scenarios about it.
Not measured
None of our checks observes evidence for this item.

An item takes the strongest strength among its rows. An item with no rows is NOT_MEASURED. A model-comparison bank counts for an item only when the bank's stated task targets it; a bank that touches the item in one or two questions is noted but not counted.

OWASP ASI Top 10 (2026)

  1. ASI01 Agent Goal Hijack

    Not measured

    Nothing we run injects instructions through content, tools or retrieved data and then watches whether an agent's goal changes. The safety axis measures refusal of direct requests, which is not resistance to goal hijack.

  2. ASI02 Tool Misuse and Exploitation

    Partial
  3. ASI03 Identity and Privilege Abuse

    Partial
  4. ASI04 Agentic Supply Chain Vulnerabilities

    Partial
  5. ASI05 Unexpected Code Execution (RCE)

    Partial
    • Measures how well models used as a guard flag code that spawns a shell or escapes a sandbox. It measures one detection layer on a frozen bank, not whether any agent executes code.

      Live data: /api/gspc?axis=jail

  6. ASI06 Memory & Context Poisoning

    Not measured

    Nothing we run writes to an agent's memory or retrieved context and then reads back its later behaviour. The swarm bank has two questions on shared-memory poisoning; under the counting rule that does not make it evidence for this item.

  7. ASI07 Insecure Inter-Agent Communication

    Direct
  8. ASI08 Cascading Failures

    Partial
    • Includes questions on injected instructions spreading between agents, supervisors that fail open and agents spawning agents without limit. These are model answers on a frozen bank; no system is run until it fails.

      Live data: /api/gspc?axis=swarm

  9. ASI09 Human-Agent Trust Exploitation

    Partial
  10. ASI10 Rogue Agents

    Not measured

    Nothing we run watches an agent over time for behaviour that departs from its purpose without an attacker. The jail bank classifies code cells; it does not observe an agent.

OWASP MCP Top 10 (beta)

Beta. The project road map says it is in Phase 3, 'Beta Release and Pilot Testing', with the next release planned for October 2026.

  1. MCP01:2025 Token Mismanagement & Secret Exposure

    Not measured

    We do not scan servers, logs or model memory for exposed secrets or token lifetimes.

  2. MCP02:2025 Privilege Escalation via Scope Creep

    Partial
  3. MCP03:2025 Tool Poisoning

    Partial
  4. MCP04:2025 Software Supply Chain Attacks & Dependency Tampering

    Partial
  5. MCP05:2025 Command Injection & Execution

    Partial
  6. MCP06:2025 Intent Flow Subversion

    Not measured

    Nothing we run plants instructions in retrieved context and watches whether an agent's intent changes.

  7. MCP07:2025 Insufficient Authentication & Authorization

    Direct
  8. MCP08:2025 Lack of Audit and Telemetry

    Not measured

    We do not observe the logs or telemetry any server keeps.

  9. MCP09:2025 Shadow MCP Servers

    Not measured

    Shadow servers are, by definition, outside the public registries our census reads.

  10. MCP10:2025 Context Injection & Over-Sharing

    Not measured

    Nothing we run shares context across sessions, users or agents and looks for leakage.

The checks

Counts shown beside each census check are read by the generator from the committed record files named in the JSON, with their as_of. GSPC axes carry no count here; follow the live link.

The census checks are published as signed measurement capsules, one adapter per kind; see measurement capsules.

  • contract_parity: carries MCP contract parity: TOOLS; MCP contract parity: VERSION; MCP contract parity: PROTOCOL; MCP contract parity: AUTH; MCP contract parity: PAYMENT (record)
  • a2a_card: carries A2A agent-card signature verification (record)
  • tool_drift: carries MCP tool drift (record)
  • cross_ledger: Tokenised-asset supply across ledgers; bears on no item. (record)
  • mill_cross_runtime: Whether a model's measured result reproduces on a second runtime; bears on no item. (record)
  • public_signals: Outside signals about CSOAI itself; bears on no item. (record)
  • self_parity: What outside indexes say about our own offerings; bears on no item. (record)

What we measure that maps to neither list

  • MCP contract parity: PAYMENT: Payment-term consistency bears on no item in either list.
  • x402 door conformance: It checks the shape of our own payment challenges, which bears on no item in either list.
  • governance axis: EU AI Act risk-tier classification; no agentic threat surface. (live)
  • safety axis: Refusal of direct requests. No injected or indirect instruction is present, so it is not evidence about goal hijack. (live)
  • provenance axis: Survival of synthetic-content marking; not an agentic risk in either list. (live)
  • continuity axis: Post-quantum status of cryptographic assumptions; not an agentic risk in either list. (live)
  • openness axis: Licence reasoning against intended use; not an agentic risk in either list. (live)
  • machinery-conformity axis: Classification under the EU Machinery Regulation; not an agentic risk in either list. (live)
  • care axis: Harm-avoidance trade-offs in paired conduct scenarios; bears on no single item closely enough to state. (live)
  • detector-interop axis: Cross-detector watermark interoperability; not an agentic risk in either list. (live)
  • art5-safeguard axis: Whether models refuse to build practices the EU AI Act prohibits, such as subliminal manipulation. That is refusal to build a manipulative system, not an agent exploiting a person's trust, so it is not counted for ASI09. (live)
  • provenance-controls axis: On-chain issuer control facts for tokenised assets; not an agentic risk. (live)
  • reserve-attestation axis: Issuer reserve-attestation disclosure; not an agentic risk. (live)
  • regulatory-framework axis: Whether an issuer's governing regime is declared; not an agentic risk. (live)
  • distribution-integrity axis: Token supply and holder facts; not an agentic risk. (live)
  • custody-disclosure axis: Whether a custodian and auditor are named; not an agentic risk. (live)
  • ai-adoption-components axis: Cited public statistics; not a measurement of any system. (live)
  • labour-components axis: Cited public statistics; not a measurement of any system. (live)
  • humanoid-labour-index axis: Vendor deployment disclosures; not an agentic risk. (live)

Sources and licences

OWASP Top 10 for Agentic Applications for 2026, OWASP GenAI Security Project, Agentic Security Initiative. Version 2026, December 2025, published 2025-12-09. Released.

Links: resource page, announcement, PDF (SHA-256 a2db94cd00b08e0b3a5e5b619afe024bdbcd74503111085705e4f3dd886fcb5c). Read on 2026-09-27.

ASI IDs and titles are reproduced unchanged from the OWASP Top 10 for Agentic Applications for 2026, OWASP GenAI Security Project, licensed CC BY-SA 4.0. No OWASP description text is reproduced or adapted; the rationale text is ours. Licence: CC BY-SA 4.0.

OWASP MCP Top 10, OWASP MCP Top 10 project (OWASP Foundation). Version 2025 (item IDs carry the suffix :2025). Beta. The project road map says it is in Phase 3, 'Beta Release and Pilot Testing', with the next release planned for October 2026..

Links: project, list at commit 22aff0d08e10. Read on 2026-09-27.

MCP IDs and titles are reproduced unchanged from the OWASP MCP Top 10 (beta), licensed CC BY-NC-SA 4.0. No OWASP description text is reproduced or adapted. This page is free to read and is not sold. Licence: CC BY-NC-SA 4.0. The project page links CC BY-NC-SA 4.0 and, in the same sentence, calls it the Attribution-ShareAlike licence. We follow the linked licence, which is the stricter one.

Our mapping, strengths and rationale are published under CC BY-SA 4.0. OWASP is a trademark of the OWASP Foundation; its use here identifies the source lists and implies no affiliation.

Other OWASP pages on this site

  • /owasp-agentic/: Maps ASI01 to ASI10 to the practices we apply to our own signing, keys and publishing. It describes our own controls, not measurements of other systems, and it predates the census checks used here.
  • /owasp-asi/: Despite its address, maps our axes to the OWASP AI Exchange, a different OWASP document. It does not use the ASI list.
  • measurement/owasp-asi/asi-gspc-axis-map.json: An internal axis-only map from 14 September 2026 with no strength grades. It relates jail to ASI10, cross-reality to ASI03 and art5-safeguard to ASI09; this crosswalk does not count those, for the reasons given on each check or in the unmapped list.

Edited 2026-09-27. Generated from scripts/crosswalks/owasp-asi.source.json (SHA-256 07ad1bb81b143e92…). Think a row is wrong? Email nicholas@csoai.org; changes are recorded in the corrections ledger. See also methodology.