致謝
Acknowledgements
Top 10 Leaders and Entry Leads
OWASP Top 10 for Agentic Applications 由 John Sotiropoulos(Deep Cyber)、Keren Katz(Tenable)與 Ron F Del Rosario(SAP)領導,並獲得各項 Entry Lead 的關鍵支持;若沒有他們,本文件無法完成。
| Entry | Lead(s) |
|---|---|
| ASI01 – Agent Goal Hijack | Kayla Underkoffler, Rakshith Aralimatti |
| ASI02 – Tool Misuse & Exploitation | Riggs Goodman, Gaurav Mukherjee |
| ASI03 – Identity & Privilege Abuse | Kellen Carl, Ken Huang |
| ASI04 – Agentic Supply Chain Vulnerabilities | Evgeniy Kokuykin, Aamiruddin Syed |
| ASI05 – Unexpected Code Execution (RCE) | Allie Howe, Vineeth Sai Narajala |
| ASI06 – Memory & Context Poisoning | Idan Habler, Joshua Back |
| ASI07 – Insecure Inter-Agent Communication | Stefano Amorelli, Vasilios Mavroudis |
| ASI08 – Cascading Failures | Diana Henderson |
| ASI09 – Human-Agent Trust Exploitation | Adam Morris |
| ASI10 – Rogue Agents | Tomer Elias, Mo Sadek, Priyadharhshini Parthasarathy |
Additional Contributors
- Almog Langleben, Sunbit
- Ron Bitton, Intuit
- Amritha Lal
- Kanmani Rani
- Sumeet Jeswani, Google
- Helen Oakley, SAP
- Nayan Goel, Upgrade Inc
- Rock Lambros, RockCyber
- Eva Benn, Microsoft Security
- Subaru Ueno
- John Cotter, Bentley Systems
- Josh Devon
- Mark de Rijk, Agentics Foundation
- Manish Kumar Yadav, SAP
- Sumit Ranjan, Protect Neuron
- Mohsin Khan
- Rico Komenda, Adesso SE
- Edward Bolles
- Cole Murray
- Venkata Sai Kishore Modalavalasa
- Uday Bhaskar Seelamantula, Autodesk
- Michael Marien
- Abhishek Mishra, OneTrust
- Kaustubh Phatak
- Hariprasad Holla, CrowdStrike
- Mohsin Khan
- Trent Holmes, Trend Micro
- Peter Boucher, abbView
- Emile Delcourt, Panorama Education
- Neeraj Nagpal
- Allie Howe, Growth Cyber
我們感謝 reviewers 提供具洞察力的回饋與貢獻,包括以下成員。
ASI Expert Review Board
- Alejandro Saucedo — Chair of ML Security Project at Linux Foundation, UN AI Expert, AI Expert for Tech Policy, European Commission
- Apostol Vassilev — Adversarial AI Lead, NIST
- Chris Hughes — CEO, Aquia
- Hyrum Anderson — CTO, Robust Intelligence
- Steve Wilson — OWASP GenAI Security Project Co-chair, Founder Top 10 for LLM Applications, Chief Product Officer, Exabeam
- Scott Clinton — OWASP GenAI Security Project Board Co-chair and Co-founder
- Vasilios Mavroudis — Principal Research Scientist and Theme Lead, the Alan Turing Institute
- Josh Collyer — Principal Security Researcher, Theme Lead
- Egor Pushkin — Chief Architect, Data and AI at Oracle Cloud
- Peter Bryan — Principal AI Security Research Lead - AI Red Team, Microsoft
- Daniel Jones — AI Security Researcher, AI Red Team, Microsoft
- Michael Burgury — OWASP Low-Code/No-Code Lead, OWASP AIVSS Project Co-lead, Zenity
Public Review
參與 public review 的其他組織與人員包括:
- ABN AMARO BANK — Parker Cowan
- Airbus — Kachi Agu
- AWS — Mark Keating
- Cloud Security Alliance (CSA) — Ken Huang, Jim Reavis, John Yeon
- JPMorgan — Edward Lee
- Kainos — Kyle Davidson, Tom Fowler, Daragh McConvile, Greg Wright
原作:OWASP Top 10 For Agentic Applications 2026
專案:OWASP Gen AI Security Project - Agentic Security Initiative
授權:CC BY-SA 4.0
本翻譯為非官方繁體中文版本,並依 CC BY-SA 4.0 授權釋出。