Framework Explorer

OWASP Top 10 for Agentic Applications 2026

Explore risks specific to agents that plan, use tools, retain memory, communicate, and act across workflows. Reviewed offering alignments will appear here after evidence-based vendor research; they are not vendor certifications or OWASP endorsements.

Official OWASP source

ASI01:2026

Agent Goal Hijack

Attackers manipulate an agent's objectives or decision path so it pursues unintended goals.

7 reviewed alignments
Reviewed offering assessments+
Zero Day Investigative Network · 0DIN GenAI Bug Bounty PlatformInferred alignmentmedium confidence · 1 source

0DIN crowdsources and validates exploit reports targeting chatbots, LLM applications, and autonomous AI agents.

AuditaAI assessment: exploit testing and validation for autonomous agents contributes to identifying goal-hijack and unsafe directive behavior risks.

Check Point Software Technologies · AI Agent SecurityInferred alignmentmedium confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

AuditaAI assessment: detection of direct and indirect prompt attacks in agent prompts, responses, and tool use can detect inputs used to hijack agent goals; the evidence does not establish plan-integrity verification.

Dynamo AI · AgentWardenInferred alignmenthigh confidence · 1 source

AgentWarden enforces security and authorization policies at runtime agent action boundaries across prompts, tool calls, tool responses, and final actions to prevent unauthorized execution and goal hijacking.

Enforcing action boundaries across tool calls and execution steps addresses agent goal hijacking.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: blocking prompt injection that attempts to manipulate an AI system into unintended actions addresses agent goal hijacking at the interaction boundary.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

AuditaAI assessment: stopping adversarial instructions and prompt injection before they redirect agent behavior addresses agent goal hijacking.

Promptfoo · Promptfoo EnterpriseInferred alignmenthigh confidence · 1 source

Promptfoo simulates multi-turn adaptive attacks, autonomous agent goal hijacking, tool execution vulnerabilities, and unauthorized function calls in pre-deployment CI/CD environments.

Simulating multi-turn adversarial goal hijacking directly tests defenses against agent goal redirection.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 2 sources

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: blocking prompt injection across documented agentic workflows addresses attempts to redirect an agent toward unintended goals.

ASI02:2026

Tool Misuse and Exploitation

An agent uses legitimate tools in unsafe, unintended, or attacker-directed ways.

33 reviewed alignments
Reviewed offering assessments+
Anthropic · Claude Code Security ArchitectureInferred alignmenthigh confidence · 1 source

Claude Code requires permission for state-changing file, command, and network actions before those actions execute.

AuditaAI assessment: permission gates constrain unsafe use of file, command, and network tools.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

AuditaAI assessment: Cedar policy authorizes every agent tool call and data access independently of model reasoning.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

AuditaAI assessment: agent-focused runtime controls constrain high-risk tool execution paths and unsafe autonomous actions.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

AuditaAI assessment: governance controls explicitly constrain high-risk tool usage by AI agents.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

AuditaAI assessment: allow and deny controls over tools and MCP servers, combined with contextual action evaluation, directly constrain unauthorized or unsafe tool use.

DeepKeep · DeepKeep AI Security PlatformInferred alignmenthigh confidence · 1 source

DeepKeep monitors and controls AI agent gateway usage, identifies active MCP server dependencies, and supports allow or block policy enforcement.

AuditaAI assessment: MCP usage controls and allow/block decisions address agent tool misuse risk.

Dynamo AI · AgentWardenInferred alignmenthigh confidence · 2 sources

AgentWarden analyzes reachable agent tools, external endpoints, and data sources during build time, evaluating tool combinations that present lethal trifecta risks (data access, external egress, and execution authority).

Build-time analysis of agent tools, MCP server dependencies, and parameter scopes directly addresses tool misuse and exploitation.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor sanitizes MCP tool-call requests, responses, and tool execution errors and can block content that violates configured security filters.

AuditaAI assessment: sanitizing and blocking malicious MCP tool-call requests, responses, and execution errors controls an agentic tool-use pathway; it does not establish authorization of every tool action.

Wiz · Wiz AI-SPMInferred alignmentmedium confidence · 1 source

Wiz AI-SPM identifies and classifies tools that agents can access to show the actions those agents can perform.

AuditaAI assessment: identifying tools available to agents and the actions they enable provides posture visibility into tool-misuse exposure, but the cited evidence does not establish inline prevention.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmenthigh confidence · 1 source

Glow autonomous endpoint enforcement can block unsafe agentic tool execution and unauthorized actions initiated from user devices.

AuditaAI assessment: endpoint enforcement blocks unsafe agentic tool execution and unauthorized actions before execution.

HiddenLayer · AI Runtime SecurityInferred alignmenthigh confidence · 1 source

AI Runtime Security detects and investigates prompt injection, unsafe agent behavior, sensitive data exposure, malicious tool use, and other runtime AI threats.

AuditaAI assessment: runtime detection explicitly identifies malicious tool use and unsafe agent behavior.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

AuditaAI assessment: inline runtime enforcement prevents unauthorized agent tool invocation and unsafe autonomous actions.

Maxim AI · Bifrost AI GatewayInferred alignmenthigh confidence · 2 sources

Bifrost centralizes MCP tool connections and enforces authentication, access-control, and governance policies for agent tool usage.

AuditaAI assessment: MCP tool governance and authorization boundaries reduce unsafe or attacker-directed tool misuse.

Microsoft · Microsoft Foundry Agent ServiceInferred alignmenthigh confidence · 1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

AuditaAI assessment: scoped tokens and RBAC constrain which MCP servers and downstream tools an agent can invoke; they do not validate tool arguments.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

AuditaAI assessment: controlling unsafe agentic runtime action paths constrains misuse, though the source does not identify specific tool controls.

Nightfall AI · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

AuditaAI assessment: hook-level interception and tool-call governance prevent unsafe autonomous tool actions before execution.

NVIDIA Corporation · NVIDIA OpenShellInferred alignmenthigh confidence · 2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

AuditaAI assessment: out-of-process skill and operation policy constrains unsafe or attacker-directed agent tool use.

OpenAI · OpenAI Frontier Security EvaluationInferred alignmenthigh confidence · 1 source

OpenAI Frontier integrates automated security testing and red teaming to evaluate AI coworkers for prompt injections, jailbreaks, data leaks, tool misuse, and out-of-policy behaviors.

AuditaAI assessment: pre-deployment evaluation of tool misuse and out-of-policy behaviors directly mitigates excessive agency vulnerabilities.

Pangea · Pangea AI Security PlatformInferred alignmenthigh confidence · 1 source

Pangea provides proxy-based MCP integration to apply guardrails and authentication or authorization controls to agent-to-tool and agent-to-agent communications.

AuditaAI assessment: proxy guardrails and authorization controls constrain agent-to-tool calls and tool misuse.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.

AuditaAI assessment: centralized policy governing tool calls, model access, and external connections directly controls agent tool-use pathways.

Portkey · PortkeyInferred alignmenthigh confidence · 1 source

Portkey MCP Gateway centralizes authentication, fine-grained server and tool access, observability, and runtime policy and stops unauthorized tool invocations before execution.

AuditaAI assessment: scoped server and tool access plus blocking unauthorized tool invocations before execution directly addresses tool misuse.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmenthigh confidence · 1 source

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: approving, flagging, or blocking autonomous endpoint tools directly governs tool-use risk.

Promptfoo · Promptfoo EnterpriseInferred alignmenthigh confidence · 1 source

Promptfoo simulates multi-turn adaptive attacks, autonomous agent goal hijacking, tool execution vulnerabilities, and unauthorized function calls in pre-deployment CI/CD environments.

Automated tool execution probing validates against tool abuse and unauthorized function execution.

Promptfoo · Promptfoo MCP ProxyInferred alignmenthigh confidence · 1 source

Promptfoo MCP Proxy intercepts Model Context Protocol traffic between clients and tools to evaluate tool-call authorization, parameter tampering, and excessive agency.

AuditaAI assessment: Intercepting and testing MCP tool call parameters and boundaries mitigates excessive agency and unauthorized tool execution.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

AuditaAI assessment: agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 3 sources

Cortex AI Gateway centralizes access policy, authentication, and tool-permission controls across first-party and third-party MCP-connected agent workflows.

AuditaAI assessment: centralized MCP access policy, authentication, and tool permissions constrain agent tool misuse.

Straiker · Straiker Ascend AIInferred alignmenthigh confidence · 1 source

Straiker Ascend AI runs automated adversarial testing for prompt injection, MCP tool misuse, agentic exploits, and data exfiltration risks.

AuditaAI assessment: automated adversarial testing explicitly exercises MCP tool misuse and agentic exploits as an audit control, not runtime prevention.

Teleport · Teleport MCP Access & GovernanceInferred alignmenthigh confidence · 2 sources

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

AuditaAI assessment: Role-based filtering of MCP tool calls and least-privilege scoping directly mitigate tool misuse and uncontrolled agent execution.

TrojAI · TrojAI Defend for MCPInferred alignmenthigh confidence · 1 source

TrojAI Defend for MCP discovers MCP servers and tools and enforces policy on agent-to-model-to-server communications.

AuditaAI assessment: MCP server and tool discovery plus real-time communication policy directly constrain agent tool misuse.

Verno Labs · Verno Labs AI Agent Security PlatformInferred alignmenthigh confidence · 1 source

Verno Labs provides runtime enforcement controls to constrain unsafe or unauthorized AI agent actions.

AuditaAI assessment: runtime constraints on agent actions align to reducing tool misuse and exploitation risk.

Votal AI · Votal Runtime Security PlatformInferred alignmenthigh confidence · 2 sources

Votal inspects model requests and tool calls in real time, gates tool permissions by tenant and role, and enforces policy decisions at runtime.

AuditaAI assessment: runtime policy enforcement for tool calls mitigates agent tool misuse risk.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

AuditaAI assessment: runtime boundaries that block risky tool usage and unauthorized task execution directly constrain agent tool misuse.

Zscaler · Zscaler AI BrokerInferred alignmentmedium confidence · 1 source

Zscaler AI Broker secures agentic communications through MCP and A2A brokers and enforces fine-grained access policies across enterprise AI agents.

AuditaAI assessment: MCP broker access policy constrains an agent-to-tool protocol path, but the source does not establish validation of every tool argument or action.

ASI03:2026

Identity and Privilege Abuse

Agent identities, delegated authority, or excessive privileges enable unauthorized access and actions.

19 reviewed alignments
Reviewed offering assessments+
BeyondTrust Corporation · BeyondTrust AI Agent Security & InsightsInferred alignmentmedium confidence · 1 source

BeyondTrust automatically discovers AI agents and analyzes cross-domain privilege paths.

Discovery and privilege-path analysis contribute to identity and privilege abuse detection.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

AuditaAI assessment: distinct agent identities, scoped temporary credentials, and traceable authorization chains constrain identity and privilege abuse.

Cyera · Cyera AI-SPMInferred alignmenthigh confidence · 1 source

Cyera AI-SPM maps AI assets to identities and sensitive data to identify over-permissioned agents, misconfigurations, and unauthorized data paths.

AuditaAI assessment: posture analysis identifies over-permissioned agents and unauthorized data-access paths; it does not enforce least privilege.

Cyera · Cyera Agent GuardianInferred alignmenthigh confidence · 1 source

Cyera Agent Guardian traces and governs agentic data usage across autonomous agent delegation chains, enforcing automated data access perimeters and non-human identity controls.

AuditaAI assessment: non-human identity control and automated data perimeter enforcement prevent identity and privilege abuse in autonomous agent task shifting.

Wiz · Wiz AI-SPMInferred alignmenthigh confidence · 2 sources

Wiz AI-SPM identifies posture gaps involving risky agent permissions and connects identities and access paths to AI-system exposure.

AuditaAI assessment: identifying risky agent permissions, identities, and access paths directly assesses identity and privilege abuse exposure.

Microsoft · Microsoft Foundry Agent ServiceInferred alignmenthigh confidence · 1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

AuditaAI assessment: distinct agent identities, least-privilege RBAC, scoped tokens, and independent audit trails directly address identity and privilege abuse.

NEO · Neo Security PlatformInferred alignmenthigh confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

AuditaAI assessment: prevention of over-permissioned agentic execution conditions directly addresses privilege abuse.

Okta · Okta for AI AgentsDirect alignmenthigh confidence · 2 sources

Okta registers AI agents as first-class identities in Universal Directory with mandatory human owner binding and lifecycle governance.

Agent identities with human ownership and lifecycle governance directly address identity and privilege abuse.

Ping Identity Corporation · PingOne Agent IAM CoreDirect alignmenthigh confidence · 1 source

PingOne Agent IAM Core registers AI agents as managed non-human identities with unique IDs, human ownership attribution, and dynamic scoping.

Managed non-human identities and human ownership reduce identity and privilege abuse.

Pangea · Pangea AI Security PlatformInferred alignmenthigh confidence · 1 source

Pangea provides proxy-based MCP integration to apply guardrails and authentication or authorization controls to agent-to-tool and agent-to-agent communications.

AuditaAI assessment: authentication and authorization controls on agent communications constrain identity and privilege abuse.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.

AuditaAI assessment: assigning governed identities with precise permissions and traceability directly addresses agent identity and privilege abuse.

Idira · Idira Secure AI AgentsInferred alignmenthigh confidence · 1 source

Idira Secure AI Agents acts as a dynamic agent identity broker that grants an agent access only for the duration of a specific task and automatically revokes permissions once the task completes.

AuditaAI assessment: brokering task-duration agent access and auto-revoking permissions directly limits delegated-authority and excessive-privilege abuse.

SailPoint aggregates AI agent objects, permission scopes, credentials, and ownership metadata across cloud platforms.

Agent aggregation, permissions, and ownership metadata directly address identity and privilege abuse.

Saviynt, Inc. · Saviynt Identity Security for AIDirect alignmenthigh confidence · 1 source

Saviynt binds every AI agent to a human owner sponsor for lifecycle governance and accountable execution.

Human sponsor binding and owner accountability directly address identity and privilege abuse.

Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 2 sources

Cortex AI Gateway records both agent identity and human delegator context for task-scoped attribution and governance workflows.

AuditaAI assessment: dual attribution records agent identity and human delegator context for task-scoped accountability; it is an audit control, not privilege enforcement.

Straiker · Straiker Defend AIInferred alignmenthigh confidence · 1 source

Straiker Defend AI detects and blocks identity abuse, memory poisoning, data exfiltration, and resource exploitation targeting AI agents at runtime.

AuditaAI assessment: runtime detection and blocking explicitly covers identity abuse targeting AI agents.

Teleport · Teleport MCP Access & GovernanceInferred alignmenthigh confidence · 1 source

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

AuditaAI assessment: Short-lived cryptographic certificates and zero standing privileges for agents address identity and privilege abuse.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

AuditaAI assessment: identity-aware runtime boundaries prevent over-permissioned agents from using unauthorized access paths to sensitive data.

Zscaler · Zscaler AI Access GraphInferred alignmenthigh confidence · 1 source

Zscaler AI Access Graph provides real-time visibility into how AI agents use data and identities, identifies unnecessary access, and tracks data lineage across channels.

AuditaAI assessment: mapping agent identity and data use and identifying unnecessary access directly assesses agent identity and privilege exposure; it does not itself prove revocation.

ASI04:2026

Agentic Supply Chain Vulnerabilities

Compromised agent components, tools, models, plugins, or dependencies undermine agent behavior and trust.

11 reviewed alignments
Reviewed offering assessments+
Chainguard · Chainguard Secure AI SDLCInferred alignmenthigh confidence · 1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

AuditaAI assessment: trusted dependencies, CI/CD integrity, and hardened runtime foundations protect software components used by agentic systems.

Chainguard · Chainguard LibrariesInferred alignmenthigh confidence · 1 source

Chainguard Libraries provides a malware-resistant dependency catalog intended to replace direct reliance on public package registries.

AuditaAI assessment: malware-resistant built-from-source dependencies reduce compromise of components consumed by agentic systems.

Chainguard · Chainguard FactoryInferred alignmenthigh confidence · 1 source

Chainguard Factory applies SHA-pinned source inputs, isolated SLSA L3 build controls, cryptographic signing, and reproducibility checks when producing artifacts.

AuditaAI assessment: pinned inputs, isolated SLSA builds, signing, and reproducibility protect agentic software artifacts from supply-chain tampering.

Cisco · AI Supply Chain Risk ManagementInferred alignmentmedium confidence · 1 source

Cisco AI Supply Chain Risk Management provides governance and security over AI models and files used by AI applications and agents.

AuditaAI assessment: governance and security over AI models and files provides agentic supply-chain posture; the source does not establish cryptographic integrity enforcement.

Wiz · Wiz AI-BOMInferred alignmentmedium confidence · 1 source

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: continuous inventory of AI frameworks, SDKs, dependencies, identities, and access paths provides visibility into agentic supply-chain exposure; the evidence does not establish prevention of compromise.

HiddenLayer · AI Supply Chain SecurityInferred alignmenthigh confidence · 1 source

AI Supply Chain Security analyzes model architectures, layers, weights, and artifacts for tampering or anomalies and tracks model lineage, origin, and licensing.

AuditaAI assessment: artifact tampering and anomaly inspection plus lineage tracking protect model components used by agents.

Lasso Security · AI Security Posture ManagementInferred alignmentmedium confidence · 2 sources

Lasso AI Security Posture Management evaluates misconfigurations and policy gaps, including supply-chain-oriented risk indicators before production rollout.

AuditaAI assessment: pre-production supply-chain risk indicators provide posture coverage, not component integrity enforcement.

Microsoft · Microsoft Defender for Cloud (AI-SPM)Inferred alignmentmedium confidence · 1 source

Defender for Cloud AI posture capabilities discover and inventory AI resources and workloads for security posture visibility.

AuditaAI assessment: Defender AI BOM discovery and dependency-vulnerability visibility provide agentic supply-chain posture, not component integrity enforcement.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS scans agent code, MCP servers, and skills for unsafe permissions, hidden vulnerabilities, and indirect injection paths.

AuditaAI assessment: scanning agent code, MCP servers, and skills for unsafe permissions and hidden vulnerabilities addresses agentic supply-chain exposure.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmenthigh confidence · 1 source

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: real-time code-difference and behavioral-shift analysis identifies supply-chain changes affecting autonomous software and AI agents.

SPLX · SPLX AI Asset ManagementInferred alignmentmedium confidence · 2 sources

Zscaler AI Security discovers and maps AI applications, models, MCP servers, development tools, data pipelines, and related risks.

AuditaAI assessment: AI BOM inventory of models, MCP servers, development tools, and pipelines provides visibility into agentic supply-chain exposure; it does not establish component integrity enforcement.

ASI05:2026

Unexpected Code Execution

Agent-generated or agent-selected code executes without sufficient validation, isolation, or control.

4 reviewed alignments
Reviewed offering assessments+
Anthropic · Claude Code Security ArchitectureInferred alignmenthigh confidence · 1 source

Claude Code constrains command execution with operating-system sandbox boundaries that limit filesystem and network access.

AuditaAI assessment: operating-system sandboxing constrains unexpected code execution selected by an agent.

NVIDIA Corporation · NVIDIA NemoClawInferred alignmenthigh confidence · 2 sources

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

AuditaAI assessment: hardened filesystem and process boundaries isolate unexpected code execution selected by an autonomous agent.

NVIDIA Corporation · NVIDIA OpenShellInferred alignmenthigh confidence · 2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

AuditaAI assessment: isolated sandboxes and process, filesystem, and network policy constrain unexpected agent-selected code execution.

Teleport · Teleport BeamsInferred alignmenthigh confidence · 1 source

Teleport Beams provisions ephemeral Firecracker microVMs with file system and network isolation to execute infrastructure AI agents without static credentials.

AuditaAI assessment: Firecracker microVM execution sandboxing provides strict containment for autonomous infrastructure agents.

ASI06:2026

Memory and Context Poisoning

Malicious or corrupted information persists in agent memory or context and influences later decisions.

3 reviewed alignments
Reviewed offering assessments+
Cyera · Cyera Agent GuardianInferred alignmenthigh confidence · 2 sources

Cyera Agent Guardian traces and governs agentic data usage across autonomous agent delegation chains, enforcing automated data access perimeters and non-human identity controls.

AuditaAI assessment: tracing and governing data lake usage across agent chains of delegation directly protects memory and context integrity against unauthorized data leakage.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

AuditaAI assessment: runtime prevention explicitly includes memory manipulation and adversarial instructions affecting agents.

Straiker · Straiker Defend AIInferred alignmenthigh confidence · 1 source

Straiker Defend AI detects and blocks identity abuse, memory poisoning, data exfiltration, and resource exploitation targeting AI agents at runtime.

AuditaAI assessment: runtime detection and blocking explicitly covers memory poisoning targeting AI agents.

ASI07:2026

Insecure Inter-Agent Communication

Insufficiently authenticated, authorized, or validated communication permits manipulation between agents.

7 reviewed alignments
Reviewed offering assessments+
Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore applies identity and authorization controls to agents using MCP and A2A communications with external tools and other agents.

AuditaAI assessment: agent identity and independent authorization protect MCP and A2A communications.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Through Agent Gateway, Model Armor screens and can block policy-violating traffic between agents and clients, external systems, MCP servers, third-party AI agents, and other AI agents.

AuditaAI assessment: screening and blocking policy-violating traffic between agents, external agents, MCP servers, and other systems addresses insecure inter-agent communication content paths.

Microsoft · Microsoft Foundry Agent ServiceInferred alignmenthigh confidence · 1 source

Microsoft Foundry uses agent identities and audience-scoped tokens to authenticate Agent-to-Agent endpoints and allow downstream services to grant or deny access through RBAC.

AuditaAI assessment: dedicated agent identities and audience-scoped tokens authenticate and authorize A2A communication endpoints.

Pangea · Pangea AI Security PlatformInferred alignmenthigh confidence · 1 source

Pangea provides proxy-based MCP integration to apply guardrails and authentication or authorization controls to agent-to-tool and agent-to-agent communications.

AuditaAI assessment: proxy-based authentication, authorization, and guardrails directly protect agent-to-agent communications.

Snowflake Inc. · Cortex AI GatewayInferred alignmentmedium confidence · 3 sources

Cortex AI Gateway centralizes access policy, authentication, and tool-permission controls across first-party and third-party MCP-connected agent workflows.

AuditaAI assessment: centralized authentication and access policy protect MCP-connected agent communications; the evidence does not establish direct A2A message integrity.

TrojAI · TrojAI Defend for MCPInferred alignmentmedium confidence · 1 source

TrojAI Defend for MCP discovers MCP servers and tools and enforces policy on agent-to-model-to-server communications.

AuditaAI assessment: policy enforcement protects agent-to-model-to-server MCP communications; the evidence does not establish A2A identity or message integrity.

Zscaler · Zscaler AI BrokerInferred alignmenthigh confidence · 1 source

Zscaler AI Broker secures agentic communications through MCP and A2A brokers and enforces fine-grained access policies across enterprise AI agents.

AuditaAI assessment: securing MCP and A2A communications through brokers with fine-grained access policy directly addresses insecure agent communication paths.

ASI08:2026

Cascading Failures

An agent error or compromise propagates across connected agents, tools, systems, or workflows.

1 reviewed alignment
Reviewed offering assessments+
Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

AuditaAI assessment: stopping threats before they propagate across an agent swarm addresses cascading compromise propagation; the source does not establish recovery after failure.

ASI09:2026

Human-Agent Trust Exploitation

Attackers exploit human trust in agent outputs, identity, or authority to influence consequential decisions.

3 reviewed alignments
Reviewed offering assessments+
Anthropic · Claude Code Security ArchitectureInferred alignmentmedium confidence · 1 source

Claude Code requires permission for state-changing file, command, and network actions before those actions execute.

AuditaAI assessment: explicit approval keeps a human decision point before consequential agent actions.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

AWS supports human approval hooks for high-consequence agent actions and behavioral monitoring for actions outside an agent's authorized scope.

AuditaAI assessment: explicit human approval gates high-consequence agent actions and preserves accountable human authority.

NVIDIA Corporation · NVIDIA NemoClawInferred alignmentmedium confidence · 1 source

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

AuditaAI assessment: operator approval for blocked destinations preserves a human decision point before expanding agent authority.

ASI10:2026

Rogue Agents

An agent operates outside intended oversight, policy, or control and takes harmful or unauthorized actions.

9 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmentmedium confidence · 1 source

Cranium discovers agents across enterprise environments, surfaces shadow AI, and records ownership and usage context in a living system of record.

AuditaAI assessment: discovery of agents and shadow AI with ownership and usage context provides rogue-agent posture visibility, not containment.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmentmedium confidence · 1 source

Amazon Bedrock AgentCore Registry catalogs agents and MCP servers for centralized governance and observability.

AuditaAI assessment: centralized agent and MCP registration provides governance visibility into unauthorized agents; it does not establish containment.

Check Point Software Technologies · AI Agent SecurityInferred alignmentmedium confidence · 1 source

AI Agent Security discovers agents and assesses their tool and MCP access surface for security risk.

AuditaAI assessment: agent discovery and risk assessment provide posture visibility into unauthorized or unsafe agents and their tool surface; the claim does not establish containment.

Wiz · Wiz AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

Wiz AI Runtime Protection detects prompt injection, rogue agents, and malicious behavior targeting AI systems.

AuditaAI assessment: runtime detection explicitly includes rogue agents and malicious behavior targeting AI systems.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

AuditaAI assessment: runtime workflows detect, contain, and remediate unsafe agent behavior and unauthorized action chains.

Microsoft · Microsoft Agent 365Inferred alignmentmedium confidence · 2 sources

Microsoft Agent 365 powers a centralized inventory and posture view of Microsoft and supported non-Microsoft agents, including identities, tools, MCP servers, risk indicators, alerts, and recommendations.

AuditaAI assessment: cross-platform agent inventory, risk indicators, alerts, and recommendations provide posture visibility into unauthorized or unsafe agents; the claim does not establish containment.

Palo Alto Networks · Prisma AIRSInferred alignmentmedium confidence · 1 source

Prisma AIRS maps enterprise, endpoint, and browser agents and surfaces MCP servers, plugins, tool interactions, shadow AI, and unsanctioned agents.

AuditaAI assessment: bringing unsanctioned agents and their tool interactions into view provides posture visibility into rogue-agent exposure, not proof of containment.

Straiker · Straiker Discover AIInferred alignmentmedium confidence · 1 source

Straiker Discover AI maps AI agents, MCP servers, and agentic workflows and provides posture monitoring and misconfiguration detection.

AuditaAI assessment: mapping agents, MCP servers, workflows, and misconfigurations provides posture visibility into unauthorized or unsafe agents; it does not establish containment.

Zenity · AI ObservabilityInferred alignmentmedium confidence · 2 sources

Zenity AI Observability builds live inventory of agents, owners, permissions, and touched data across SaaS, cloud, and endpoint environments.

AuditaAI assessment: live inventory of agents, owners, permissions, and data touchpoints provides posture visibility into unauthorized or unsafe agents; it does not by itself establish containment.