OWASP Agentic & AI Agent Security
Tool misuse, excessive agency, memory poisoning, human approval, output validation, data protection, monitoring and resource limits.
Mappings provide traceability, not certification. A mapped finding shows why a control matters and where remediation supports a broader framework.
Tool misuse, excessive agency, memory poisoning, human approval, output validation, data protection, monitoring and resource limits.
Supply-chain exposure, improper output handling and unbounded consumption are mapped directly from observed technical evidence.
GOVERN, MEASURE and MANAGE references connect technical findings with risk ownership, evaluation and treatment activities.
CI/CD, immutable dependencies, build integrity, repository governance and vulnerability-reporting controls.
| Finding | Observed risk | Example mapping |
|---|---|---|
| ARL-MCP-001 | Shell-capable agent tool | OWASP Agentic: Tool Misuse |
| ARL-AI-008 | Unscoped persistent memory | OWASP Agentic: Memory Poisoning |
| ARL-CICD-001 | Broad workflow permissions | NIST AI RMF GOVERN 1.7 |
| ARL-DEP-001 | Missing dependency lockfile | SLSA Build |
The complete machine-readable mapping is published in the Inspector policy catalogue and embedded in SARIF rules.
Open complete policy catalogue Run a scan