Every agentic finding carries the ASI-NN identifier with the specific tool or chain that triggered it
.
OWASP Agentic Top 10 (2026) is the community-curated list of the most critical security risks for agentic AI systems: tool poisoning, excessive agency, agentic-loop exploits, confused deputy, and more.
Last reviewed July 2026
An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.
Penaxtra catalogues agents + MCP servers + tools as first-class assets and ships probe families across ASI01-ASI10. Runtime tool-allowlist enforcement aligns to ASI03 (excessive agency).
.
A tool-poisoning chain that escalates from a read-only knowledge tool to a write tool is tagged ASI02 (tool poisoning) and ASI03 (excessive agency).
Each control has a dedicated page: what it covers and how Penaxtra tests and evidences it.