AISecurity

OWASP Agentic AI Top 10 (2026) — SENTINEL Coverage Mapping

Updated: 2026-02-26 Source: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

Coverage Summary

Coverage Count
✅ Full 9/10
⚠️ Partial 1/10
❌ None 0/10

The full platform (sentinel-core + shield + immune) achieves 9/10 coverage. Sentinel Lattice primitives (TSA, L2, AAS, CAFL, GPS, IRM, MIRE, PASR) provide formal-methods coverage that no pattern-matching tool can achieve alone.


Detailed Mapping

✅ ASI01 — Agent Goal Hijack

Risk: Attacker alters agent’s objectives through malicious content

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + formal methods)


✅ ASI02 — Tool Misuse and Exploitation

Risk: Agent uses legitimate tools in unsafe/unintended ways

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + capability enforcement)


✅ ASI03 — Identity and Privilege Abuse

Risk: Agent escalates privileges or abuses inherited credentials

SENTINEL Coverage (Rust):

Status: FULLY COVERED (detection + runtime enforcement via shield trust zones + immune syscall hooks)


✅ ASI04 — Agentic Supply Chain Vulnerabilities

Risk: Poisoned RAG data, vulnerable tools/plugins, compromised models

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + provenance tracking)


⚠️ ASI05 — Unexpected Code Execution (RCE)

Risk: Agent generates and executes malicious code

SENTINEL Coverage (Rust):

Gap: Linux sandbox is stub (no namespaces/seccomp) — BSD jail only

Status: PARTIAL (detection + BSD sandbox via immune jail, no Linux sandbox)


✅ ASI06 — Memory and Context Poisoning

Risk: Malicious data injected into agent’s long-term memory

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + formal temporal/argument analysis)


✅ ASI07 — Insecure Inter-Agent Communication

Risk: Message forging/impersonation between agents

SENTINEL Coverage (Rust):

Status: FULLY COVERED (detection + containment + production-grade mTLS + crypto auth)


✅ ASI08 — Cascading Failures

Risk: Small error triggers destructive chain reaction

SENTINEL Coverage (Rust):

Status: FULLY COVERED (runtime cascade monitoring via shield watchdog + circuit breaker + immune XDR correlation)


✅ ASI09 — Human-Agent Trust Exploitation

Risk: Agent output deceives human into approving malicious action

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + formal argumentation/intent)


✅ ASI10 — Rogue Agents

Risk: Agents acting outside intended parameters

SENTINEL Coverage (Rust):

Status: FULLY COVERED (pattern + formal containment/predictability)


Sentinel Lattice Impact Summary

Lattice Engine Primitive ASI Coverage
TSA Temporal Safety Automata ASI03, ASI06, ASI10
L2 Capability Proxy + IFC ASI02, ASI03
AAS Adversarial Argumentation ASI06, ASI09
CAFL Capability-Attenuating Flow ASI02, ASI08
GPS Goal Predictability Score ASI01, ASI10
IRM Intent Revelation ASI01, ASI09
MIRE Model-Irrelevance Containment ASI07, ASI10
PASR Provenance-Annotated Reduction ASI04
shield watchdog Cascade Monitoring ASI08
shield circuit_breaker Failure Isolation ASI08
immune mTLS + crypto Agent Authentication ASI07
immune jail Process Isolation ASI05
immune syscall hooks Privilege Monitoring ASI03
immune XDR correlator Attack Propagation ASI08

References

  1. OWASP Agentic Top 10: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
  2. Sentinel Lattice paper: papers/sentinel-lattice/main.pdf
  3. Engine reference: docs/reference/engines-en.md