RU · ПУБЛИЧНЫЙ ПРОДУКТОВЫЙ СЛОЙ
Universe
OWASP / СОПОСТАВЛЕНИЕ AGENTIC SECURITY

OWASP Top 10 for Agentic Applications — как это сопоставлено с тестами BitEvo

OWASP опубликовал Top 10 for Agentic Applications 9 декабря 2025 года. BitEvo проверяет цепочку действий одного workflow в staging или test. Таблица показывает, какие из семи ворот BitEvo относятся к каждому риску, какие доказательства мы ищем и где заканчивается scope.

ASI01–ASI10

Риск → ворота → доказательства → граница scope

ASI01 · OWASP risk

Agent Goal Hijack

BitEvo gates: Authority Budget · Evidence Before Effect

Evidence we look for

The attempted action and the rule that allowed or refused it

Scope note

We test what a hijacked agent can still do, not whether the model resists injected text

ASI02 · OWASP risk

Tool Misuse and Exploitation

BitEvo gates: Authority Budget · Object binding

Evidence we look for

The object ID checked before execution, and the ID that actually changed

Scope note

Core scope

ASI03 · OWASP risk

Identity and Privilege Abuse

BitEvo gates: Authority owner · Authority Budget

Evidence we look for

The grant or approval record that links the role to the action

Scope note

Core scope

ASI04 · OWASP risk

Agentic Supply Chain Vulnerabilities

BitEvo gates: Authority Budget

Evidence we look for

Which third-party tools and MCP servers can act, and with what permissions

Scope note

We map their authority; we do not audit their code

ASI05 · OWASP risk

Unexpected Code Execution (RCE)

BitEvo gates: Authority Budget

Evidence we look for

Whether code execution is an allowed action at all, and for which inputs

Scope note

Exploit development is out of scope

ASI06 · OWASP risk

Memory & Context Poisoning

BitEvo gates: Freshness · Evidence Before Effect

Evidence we look for

Time, source and version of each item the agent relied on at decision time

Scope note

We test whether stale or unverified context can trigger an action

ASI07 · OWASP risk

Insecure Inter-Agent Communication

BitEvo gates: Authority owner · External confirmation

Evidence we look for

Who delegated authority between agents, and independent confirmation of the effect

Scope note

Within the one workflow in scope

ASI08 · OWASP risk

Cascading Failures

BitEvo gates: Recovery · External confirmation

Evidence we look for

The state change when confirmation is missing, and who released the workflow

Scope note

Core scope: retries, resume, duplicate effects

ASI09 · OWASP risk

Human-Agent Trust Exploitation

BitEvo gates: External confirmation · Authority owner

Evidence we look for

Whether "done" was reported before the external system confirmed it, and what the approver was shown

Scope note

We test approval evidence, not user training

ASI10 · OWASP risk

Rogue Agents

BitEvo gates: Authority Budget · Recovery

Evidence we look for

Actions outside the agreed budget, and the stop or constrained state that follows

Scope note

Detection tooling is out of scope

Граница сопоставления

Сопоставление BitEvo предназначено для определения scope.

Это не сертификация и не одобрение OWASP.