OWASP coverage matrix
Generated by
pnpm gen:coveragefrom rulethreatsmetadata and eval cases — never hand-edited. Catalog version 2026.08.0 (OWASP LLM Top 10 2026 · Agentic/ASI Top 10 2026). "Verified by attack cases" lists built-in dataset attacks that actually hit the threat — claiming coverage and having verified it are different things.
OWASP Top 10 for LLM Applications 2026
| Threat | Title | Covering rules | Verified by attack cases |
|---|---|---|---|
| LLM01:2026 | Prompt Injection | input-hygieneinjection.block (probabilistic)injection.defang (probabilistic)spotlight.delimit (probabilistic)lethal-trifecta | inj-override-zhinj-override-eninj-persona-hijackinj-unicode-taginj-zero-widthinj-control-charsinj-tool-resultinj-forged-freeze-markexp-novel-phrasingexf-lethal-trifecta |
| LLM02:2026 | Sensitive Information Disclosure | lethal-trifectapii.redactrow-filterfield-mask | exf-lethal-trifectaout-pii-leakdat-row-exfil |
| LLM03:2026 | Excessive Agency | rbac-tool-gateapproval-gate | dat-no-identitydat-unknown-roledat-tool-escapedat-big-refunddat-missing-amount |
| LLM04:2026 | Supply Chain | — not covered | — |
| LLM05:2026 | Data and Model Poisoning | — not covered | — |
| LLM06:2026 | Unbounded Consumption | max-lengthoutput-caps | inj-flood |
| LLM07:2026 | Misinformation | citation-faithfulnessnumeric-trace | out-ungrounded-numberout-userstated-commitout-fake-citationout-refusal-smuggle |
| LLM08:2026 | Hidden Context Exposure | — not covered | — |
| LLM09:2026 | Vector and Embedding Weaknesses | citation-faithfulness | out-fake-citation |
| LLM10:2026 | Improper Output Handling | link-policy | exf-output-link |
OWASP Top 10 for Agentic Applications 2026
| Threat | Title | Covering rules | Verified by attack cases |
|---|---|---|---|
| ASI01:2026 | Agent Goal Hijack | injection.block (probabilistic)injection.defang (probabilistic) | inj-override-zhinj-override-eninj-persona-hijack |
| ASI02:2026 | Tool Misuse and Exploitation | lethal-trifectalink-policyrbac-tool-gateapproval-gate | exf-lethal-trifectaexf-output-linkdat-tool-escapedat-big-refund |
| ASI03:2026 | Identity and Privilege Abuse | rbac-tool-gate | dat-no-identitydat-unknown-roledat-tool-escape |
| ASI04:2026 | Agentic Supply Chain Vulnerabilities | — not covered | — |
| ASI05:2026 | Unexpected Code Execution (RCE) | — not covered | — |
| ASI06:2026 | Memory & Context Poisoning | spotlight.delimit (probabilistic) | inj-tool-resultinj-forged-freeze-mark |
| ASI07:2026 | Insecure Inter-Agent Communication | — not covered | — |
| ASI08:2026 | Cascading Failures | — not covered | — |
| ASI09:2026 | Human-Agent Trust Exploitation | — not covered | — |
| ASI10:2026 | Rogue Agents | — not covered | — |
Not covered: LLM04:2026, LLM05:2026, LLM08:2026, ASI04:2026, ASI05:2026, ASI07:2026, ASI08:2026, ASI09:2026, ASI10:2026. The gaps are facts, not omissions.