OWASP Agentic Top 10 Compliance Mapping
OWASP Agentic Top 10 (2026) is the community-curated list of the most critical security risks for agentic AI systems: tool poisoning, excessive agency, agentic-loop exploits, confused deputy, and more.
Last reviewed September 2026
Why OWASP Agentic Top 10 evidence is hard
An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.
How Penaxtra maps to OWASP Agentic Top 10
Penaxtra catalogues agents + MCP servers + tools as first-class assets and ships probe families across ASI01-ASI10. Runtime tool-allowlist enforcement aligns to ASI03 (excessive agency).
OWASP Agentic Top 10 capabilities
Audit-ready PDF export with control IDs attached
JSON export for GRC ticketing systems
Configurable audit retention from 1 day to 10 years
Cross-framework overlaps reduce duplicate evidence collection
OWASP Agentic Top 10 control coverage
A tool-poisoning chain that escalates from a read-only knowledge tool to a write tool is tagged ASI02 (tool poisoning) and ASI03 (excessive agency).
Controls in this framework
Each control has a dedicated page: what it covers and how Penaxtra tests and evidences it.