Overview
The first two crosswalks in this chapter answered a threat model and a requirements framework. This one answers the checklist. When a security team reviews an agent deployment, the framing on the table is usually OWASP’s: the Agentic AI Threats and Mitigations taxonomy from the GenAI Security Project (first published in February 2025 with fifteen threats, revised to version 1.1 in December 2025 with seventeen, and distilled the same month into the Top 10 for Agentic Applications for 2026, mapped below), seventeen threats spanning single agents, multi-agent systems, their protocols and supply chains, and the humans around them, alongside the Top 10 for LLM Applications, now in its 2026 edition. If the handbook cannot state its position against that list, threat by threat, the reviewer is right to treat it as unevaluated.
A crosswalk that claims everything has been fitted to its framing, so this one sorts every threat into three verdicts, each stated as what an attacker can still do:
| Verdict | What it means |
|---|---|
| Contained | The attacker cannot exceed the authority the Mission committed or keep it past the Mission’s end, and machinery built for the threat, with a draft behind it, enforces that. Inside the committed authority, the attacker can still act |
| Bounded | The cause is out of authorization’s reach: the attacker can still poison, steer, or deceive, and the action gate caps what any resulting action can do |
| Delegated | Not an authorization problem: a named complement owns it, and the handbook composes with it |
The distinction that drives most rows is the one the trifecta post established: the authorization layer does not make the model resistant to anything. It makes the model’s compromise survivable, because authority was fixed at approval and every consequential action is checked against it fresh. A verdict follows what the threat attacks. Threats that attack authority are contained. Threats that attack the agent, its memory, its goals, its inputs, or the humans around it are bounded, even where the gate also stops the resulting action from exceeding the committed authority, because the cause is untouched. Threats that attack layers the handbook never claimed are delegated, by name. So contained never means prevented at the cause: a manipulated goal, a misused tool, or a rogue instance can still act inside the committed authority, which is why scope stays tight. Throughout the chapter, the gate checks a committed boundary and never an inferred intent.
The agentic threats, all seventeen
| Threat | The attack | The handbook’s answer | Verdict |
|---|---|---|---|
| T1 Memory Poisoning | Persistent memory is seeded with malicious data that steers future behavior | Poisoned memory can steer proposals, not authority: shaping fails closed on ambiguity, and every consequential action still needs a fresh parameter-bound permit against the approved Mission | Bounded |
| T2 Tool Misuse | The agent’s own tools are driven to unauthorized or harmful invocations | Per-action PEP/PDP enforcement with parameters bound into the permit, applied at the tool boundary by the MCP application post | Contained |
| T3 Privilege Compromise | Permissions escalate beyond what the task requires | Narrowing: every derivation is a strict subset of the Mission’s Authority Set, Child Missions only narrow, and there is no ambient inheritance to escalate into | Contained |
| T4 Resource Overload | Unbounded agent activity exhausts compute, API, or financial budgets | expires_at on every Mission, fan-out bounded by count and depth, and Consumption Metering (experimental) for spend | Bounded |
| T5 Cascading Hallucination Attacks | False content propagates through memory, messages, and downstream systems | Authorization does not verify truth. It gates consequence: hallucinated content can only reach the world through consequential actions, each needing its own permit | Bounded |
| T6 Intent Breaking and Goal Manipulation | Injection or instruction manipulation redirects the agent’s objectives | The manipulation itself is untouched: the agent’s goal can be rewritten. The rewritten goal cannot widen the committed one, because the PDP checks actions against the approved Mission, not against the agent’s current intent | Bounded |
| T7 Misaligned and Deceptive Behaviors | The agent acts against its intended purpose or conceals what it does | The gate does not detect deception. Only approved action classes execute, and Decision and Execution Evidence come from the gate, not from the agent’s self-report | Bounded |
| T8 Repudiation and Untraceability | Actions cannot be reliably attributed or audited | Attribution end to end: the act chain on every hop, the evidence family joined on mission_id, and SCITT keeping the feed tamper-evident | Contained |
| T9 Identity Spoofing and Impersonation | Attackers assume an agent’s identity or abuse non-human authentication | Attested instance identity, sender-constrained tokens, and mediated custody keeping the credential out of the agent entirely for mediated classes | Contained |
| T10 Overwhelming the Human in the Loop | Approval volume is weaponized until humans rubber-stamp | Human decisions stay rare and consequential by design: the PDP decides individual actions, a deterministic policy can adjudicate activation within a ceiling a human consented to, and humans stay accountable for the ceilings and keep the class-guard classes, with deferred approval and the batched discovery loop absorbing the volume | Bounded |
| T11 Unexpected RCE and Code Attacks | Tool invocations achieve code execution | Sandboxing owns execution. The handbook gates what executed code can reach: consequential effects still need permits, and capabilities are bound to source digests with drift failing closed | Bounded |
| T12 Agent Communication Poisoning | Malicious instructions ride inter-agent messages | Influence carries no authority between agents, because delegation only narrows and every hop is enforced against its own Child Mission | Bounded |
| T13 Rogue Agents | A compromised agent inside the system acts maliciously | The compromise itself is untouched. A rogue instance holds only mission-bound, instance-bound, revocable authority, and Termination cascades through the delegation tree to issuance, permits, and the harness on the paths the deployment governs | Bounded |
| T14 Human Attacks on Multi-Agent Systems | Operators are manipulated into enabling harm | Social engineering is out of authorization’s reach. What holds: a manipulated operator can still only approve what shaping renders, and the approval is attributed to them | Bounded |
| T15 Human Manipulation | The agent deceives its own human into approving or enabling harm | Consent Evidence commits the disclosure as rendered, so the record shows what the trusted approval surface committed, never what the human perceived or understood. An accurately disclosed bad idea remains the human’s decision, and the record says so | Bounded |
| T16 Insecure Inter-Agent Protocol Abuse | Protocol weaknesses let attackers manipulate coordination messages, memory, or protocol logic to bypass safeguards, including skipped consent checks | A skipped protocol step cannot mint authority: approval is an event at the Mission Issuer, every hop authenticates with a sender-constrained credential, and each consequential action is checked against that hop’s own Child Mission. The protocol weakness itself is untouched, and protocol security is the delegated layer | Bounded |
| T17 Supply Chain Compromise | Poisoned prompts, fake agent identities, tampered tool metadata, or malicious updates corrupt the agent’s logic | Model, dependency, and tool provenance belong to the software supply chain. The authorization-shaped edge: capabilities bound to source digests fail closed on drift, and a discovered tool still binds under encounter adjudication | Delegated |
Four contained, twelve bounded, and one delegated. The threats that attack authority itself (tool misuse, privilege, attribution, identity) land on machinery built for them. The threats that attack the agent, its memory, its goals, its protocols, or the humans around it are capped at the action gate: an injected goal or a rogue instance still cannot exceed the committed authority, but the cause is untouched, so those rows are bounded by the chapter’s own rule. The supply chain is another layer’s job.
The 2026 Agentic Top 10, mapped
In December 2025 the same OWASP project distilled its agentic work into the Top 10 for Agentic Applications for 2026 (ASI01 through ASI10), and that list is now the checklist most reviews open with. It compresses cleanly onto the seventeen-threat crosswalk above, so the verdicts carry over rather than multiply:
| Agentic Top 10 (2026) | Lands on | Verdict |
|---|---|---|
| ASI01 Agent Goal Hijack | T6 intent breaking: the goal can still be hijacked, and the PDP checks actions against the approved Mission, not the agent’s current goal | Bounded |
| ASI02 Tool Misuse and Exploitation | T2: per-action PEP/PDP with parameter binding at the tool boundary | Contained |
| ASI03 Identity and Privilege Abuse | T3 and T9: strict-subset derivation, attested instances, sender constraint | Contained |
| ASI04 Agentic Supply Chain Vulnerabilities | T17: the supply chain is another layer’s job, and discovered tools still bind under encounter adjudication | Delegated |
| ASI05 Unexpected Code Execution | T11: sandboxing owns execution, and consequential effects still need permits | Bounded |
| ASI06 Memory and Context Poisoning | T1: poisoned context steers proposals, never authority, and least exposure shrinks what can poison | Bounded |
| ASI07 Insecure Inter-Agent Communication | T12 and T16: influence carries no authority, since delegation only narrows and every hop re-authenticates, with transport the delegated layer | Bounded |
| ASI08 Cascading Failures | T4 and T5: expiry, fan-out bounds, metering, and cascade revocation cap the blast radius | Bounded |
| ASI09 Human-Agent Trust Exploitation | T14 and T15: disclosure integrity and the fatigue budget raise the bar, and a deceived human is still the residual | Bounded |
| ASI10 Rogue Agents | T13: the compromise is untouched, and instance-bound, mission-bound, revocable authority with cascade termination caps it | Bounded |
The tally holds the same shape: the authority-shaped risks land on machinery built for them, and the risks that live in the model, the supply chain, or the human stay bounded or delegated, stated rather than absorbed.
The LLM Top 10, split by layer
The Top 10 for LLM Applications, now in its 2026 edition, mixes layers, which makes it the better test of the delegated verdict. Half of it is not an authorization problem, and saying so is the point:
| Entry (2026 edition) | The handbook’s answer | Verdict |
|---|---|---|
| LLM01:2026 Prompt Injection | The trifecta post carries this end to end: the injected instruction cannot widen committed authority, and the external leg needs a fresh parameter-bound permit. The mechanism is T6’s, but the threat here is the injected input itself, which the gate does not prevent | Bounded |
| LLM02:2026 Sensitive Information Disclosure | Exposure discipline: bound what the agent may see as deliberately as what it may do, and mediated custody keeps credentials out of the leakable set | Bounded |
| LLM03:2026 Excessive Agency | The handbook’s subject: authority derived from an approved task, narrowed for each delegate, and checked at each consequential action | Contained |
| LLM04:2026 Supply Chain | Model and dependency provenance, owned by the software supply chain. One authorization-shaped edge: capabilities bound to source digests fail closed on drift | Delegated |
| LLM05:2026 Data and Model Poisoning | Training and embedding pipeline security, upstream of any authorization decision | Delegated |
| LLM06:2026 Unbounded Consumption | Expiry on every Mission and metering (experimental) on spend | Bounded |
| LLM07:2026 Misinformation | Content truth is semantic, and the gate is structural | Delegated |
| LLM08:2026 Hidden Context Exposure | Prompt and context hardening belongs to the model layer. What holds: authority lives in the Mission and its tokens, not in hidden context, and mediated custody keeps credentials out of the context, so exposed context discloses instructions and tool schemas, not power | Delegated |
| LLM09:2026 Vector and Embedding Weaknesses | Retrieval pipeline security. What retrieval returns is untrusted content, and the taint response treats it that way | Delegated |
| LLM10:2026 Improper Output Handling | Output is only dangerous when it acts. The consequential boundary is where the handbook stands, and nothing crosses it without a permit | Bounded |
OWASP’s mitigations for Excessive Agency are to minimize the extensions and their permissions, avoid open-ended functions, require human approval for high-impact actions, enforce authorization in downstream systems rather than trusting the model, and log everything. The handbook specifies each as protocol: authority derived from an approved task, the class guard and action-bound approval, PEP enforcement at the downstream boundary, and evidence joined on the Mission.
Three threats worth a closer look
Intent breaking is the taxonomy’s center, and the handbook’s enemy. T6 is prompt injection grown up: the attacker does not need to breach anything, only to change what the agent is trying to do. Every mitigation that asks the model to notice the manipulation is probabilistic. The handbook’s answer is the same one it gives the trifecta: the injection changed the agent’s mind, and the agent’s mind was never the source of authority. The Mission was committed at approval, the permit is checked at execution, and between those two points there is nothing the injected goal can rewrite. That is also why T6 is bounded rather than contained: the gate does not stop the manipulation, only what the manipulation can reach.
Overwhelming the human in the loop is an argument about grain. T10 is the taxonomy’s sharpest design question, because both naive answers lose: approve every action and fatigue turns humans into rubber stamps, approve nothing and governance is gone. The handbook’s grain is the Mission. A human approves the envelope once, against a committed disclosure, and the per-action volume goes to the PDP, which does not tire. When the work outgrows the envelope, the discovery loop batches the overflow into a governed expansion request instead of a stream of interrupts. The residual is real and stated: at Mission grain, approval fatigue becomes a governance discipline rather than a solved problem, disclosure quality is what stands between an approver and a reflex, and the fatigue budget collects the controls that spend against it.
A rogue agent is an insider, and every agent here is treated as one. T13 assumes the attacker is already inside the system, wearing a legitimate agent. The handbook never trusted that agent more than its paperwork: its authority is a strict subset of its parent’s, its tokens are bound to its attested instance so they do not travel, its consequential actions need permits like everyone else’s, and when it is caught, revocation cascades through the delegation tree it belongs to. The multi-agent threats (T12 through T14) all get the same structural reply: cooperation happens in messages, and messages carry no authority. T13 is bounded for the same reason T6 is: the compromise itself is untouched.
What the crosswalk does not claim
Three of this crosswalk’s ceilings are the trifecta post’s residuals, inherited unchanged. The verdicts are only as strong as PEP coverage, and an unmediated path is a threat with no verdict at all. The enforcement is structural, not semantic. And inside the approved scope, a turned agent is still turned. Two ceilings are this crosswalk’s own.
- Bounded is not prevented. For every bounded row the cause is untouched: the memory is still poisoned, the model is still fooled, the human is still tired. The gate caps what the compromise can reach, and that is the whole claim.
- The delegated rows are real dependencies. Supply chain, poisoning, retrieval security, and sandboxing are layers the handbook composes with and cannot replace. A deployment that skips them has a contained authorization layer inside an uncontained system.
The taxonomy’s own mitigation columns keep naming least privilege, human approval, complete mediation, and audit trails. The crosswalk above shows which of those the handbook turns into verifiable artifacts, and where the gate only caps what an attack can reach. The vendor test carries its six questions from here.