- LLM01
- LLM01:2026 Prompt Injection: Prompt injection resistance, direct and indirect.
- LLM03
- LLM03:2026 Excessive Agency: Excessive agency: permissions, autonomy and tool scope.
- LLM04
- LLM04:2026 Supply Chain: Model, dataset and component supply chain. The components you deploy (models, plugins, libraries) by inventory and configuration; a model’s own provenance only as its vendor documents it.
- LLM05
- LLM05:2026 Data and Model Poisoning: Integrity of training, fine-tuning and retrieval data. Retrieval data in the package; training and fine-tuning data only with access to the pipeline.
- LLM06
- LLM06:2026 Unbounded Consumption: Consumption limits and denial of wallet controls.
- LLM07
- LLM07:2026 Misinformation: Grounding of answers and safeguards against overreliance.
- LLM08
- LLM08:2026 Hidden Context Exposure: Protection of system prompts and hidden configuration.
- LLM09
- LLM09:2026 Vector and Embedding Weaknesses: Vector store and embedding isolation between users and tenants.
- LLM10
- LLM10:2026 Improper Output Handling: Validation of model output before it reaches code, browsers or databases.
- ASI01
- ASI01 Agent Goal Hijack: Agent goal integrity when inputs and documents carry instructions.
- ASI02
- ASI02 Tool Misuse and Exploitation: Tool and function calls kept within the task's intended scope.
- ASI03
- ASI03 Identity and Privilege Abuse: Agent identity, delegated credentials and privilege boundaries.
- ASI04
- ASI04 Agentic Supply Chain Vulnerabilities: Agentic supply chain: MCP servers, plugins and tool definitions.
- ASI05
- ASI05 Unexpected Code Execution (RCE): Code execution boundaries and sandboxing for agents.
- ASI06
- ASI06 Memory & Context Poisoning: Integrity of agent memory and shared context.
- ASI07
- ASI07 Insecure Inter-Agent Communication: Authentication and integrity of messages between agents.
- ASI08
- ASI08 Cascading Failures: Containment of failures that spread across agents and workflows.
- ASI09
- ASI09 Human-Agent Trust Exploitation: Human approval steps and safeguards on trusted agent output.
- ASI10
- ASI10 Rogue Agents: Detection and containment of agents that drift from their mandate.