Skip to content

OWASP coverage matrix

Generated by pnpm gen:coverage from rule threats metadata and eval cases — never hand-edited. Catalog version 2026.08.0 (OWASP LLM Top 10 2026 · Agentic/ASI Top 10 2026). "Verified by attack cases" lists built-in dataset attacks that actually hit the threat — claiming coverage and having verified it are different things.

OWASP Top 10 for LLM Applications 2026

ThreatTitleCovering rulesVerified by attack cases
LLM01:2026Prompt Injectioninput-hygiene
injection.block (probabilistic)
injection.defang (probabilistic)
spotlight.delimit (probabilistic)
lethal-trifecta
inj-override-zh
inj-override-en
inj-persona-hijack
inj-unicode-tag
inj-zero-width
inj-control-chars
inj-tool-result
inj-forged-freeze-mark
exp-novel-phrasing
exf-lethal-trifecta
LLM02:2026Sensitive Information Disclosurelethal-trifecta
pii.redact
row-filter
field-mask
exf-lethal-trifecta
out-pii-leak
dat-row-exfil
LLM03:2026Excessive Agencyrbac-tool-gate
approval-gate
dat-no-identity
dat-unknown-role
dat-tool-escape
dat-big-refund
dat-missing-amount
LLM04:2026Supply Chain— not covered
LLM05:2026Data and Model Poisoning— not covered
LLM06:2026Unbounded Consumptionmax-length
output-caps
inj-flood
LLM07:2026Misinformationcitation-faithfulness
numeric-trace
out-ungrounded-number
out-userstated-commit
out-fake-citation
out-refusal-smuggle
LLM08:2026Hidden Context Exposure— not covered
LLM09:2026Vector and Embedding Weaknessescitation-faithfulnessout-fake-citation
LLM10:2026Improper Output Handlinglink-policyexf-output-link

OWASP Top 10 for Agentic Applications 2026

ThreatTitleCovering rulesVerified by attack cases
ASI01:2026Agent Goal Hijackinjection.block (probabilistic)
injection.defang (probabilistic)
inj-override-zh
inj-override-en
inj-persona-hijack
ASI02:2026Tool Misuse and Exploitationlethal-trifecta
link-policy
rbac-tool-gate
approval-gate
exf-lethal-trifecta
exf-output-link
dat-tool-escape
dat-big-refund
ASI03:2026Identity and Privilege Abuserbac-tool-gatedat-no-identity
dat-unknown-role
dat-tool-escape
ASI04:2026Agentic Supply Chain Vulnerabilities— not covered
ASI05:2026Unexpected Code Execution (RCE)— not covered
ASI06:2026Memory & Context Poisoningspotlight.delimit (probabilistic)inj-tool-result
inj-forged-freeze-mark
ASI07:2026Insecure Inter-Agent Communication— not covered
ASI08:2026Cascading Failures— not covered
ASI09:2026Human-Agent Trust Exploitation— not covered
ASI10:2026Rogue Agents— not covered

Not covered: LLM04:2026, LLM05:2026, LLM08:2026, ASI04:2026, ASI05:2026, ASI07:2026, ASI08:2026, ASI09:2026, ASI10:2026. The gaps are facts, not omissions.