The ten agent threats
What a hijacked agent can still reach, threat by threat.
The list is the OWASP Top 10 for Agentic Applications, 2026. Each row says what the machine does about the threat today, where the evidence is, and what stays open. It speaks for the operating system only, not for a whole solution built on it. Why the kernel holds these lines at all is on Security; what it does not do yet, said plainly.
Goal hijackOWASP ASI01
The threat. A sentence planted in what the agent reads turns it to another goal.
The machine limits what the new goal can reach: no network unless declared, no route beyond its
EGRESS, no new program unless declared, no disk it did not name.
Seen in qemu_confine and qemu_egress; lessons 7 and 11.
Still open. The persuasion itself, and whatever a granted network reaches.Tool misuseOWASP ASI02
The threat. The agent uses a real tool, with real rights, for the wrong end.
The machine can run each tool as its own program, with its own needs, disks, user and budget: its reach is a line a reviewer reads, and the court refuses a need nobody granted.
Seen in the court's fixtures R17 and R18: silence is refusal.
Still open. Programs that share a disk share what is on it, and a tool's arguments are not the machine's to judge.
Identity and privilege abuseOWASP ASI03
The threat. The agent acts with more authority than its task needs.
The machine has no login, no accounts and no shell. A program runs as the user its file names, and user 0 is refused, so a program running as the machine shows up as a missing
USER line.
Seen in the court's fixtures R47 and R5; lesson 12.
Still open. A program given the disks sees the device key's disk unless its SEES leaves it out.Supply chainOWASP ASI04
The threat. A swapped library, model or plugin arrives as trusted code.
The machine installs nothing while it runs: no package manager, no store. The kernel is source fixed by its SHA-256 fingerprint, and the image is made from the file.
Seen in vendor/PIN.md.
Still open. Model files and the programs in the image carry no fingerprint yet.
Unexpected code executionOWASP ASI05
The threat. The agent is talked into running code.
The machine ships no shell, so a command string has nothing to run it. A program not allowed to start others is refused by the kernel, and a
noexec disk can be written but not run from.
Seen in qemu_confine: fork -- refused by the kernel (EPERM); fixture R5.
Still open. Code a program interprets runs inside its walls; the machine limits its reach, not its existence.Memory and context poisoningOWASP ASI06
The threat. Poisoned notes in an agent's memory re-instruct it days later.
The machine keeps each program to the disks it names, so one agent cannot write another's memory unless both name the same disk.
Seen in qemu_confine:
ledger has no sight of /var/log, caisse has no sight of /data; lesson 9.
Still open. Where a memory came from, and who may forget it, belong to a data layer that is not built.Agents talking to agentsOWASP ASI07
The threat. One agent hands another an instruction nobody reviewed.
The machine gives a program without the network nothing to talk over; such programs meet through a disk both name, a line in the file. Between boxes, a signed record is checked with the public key alone.
Seen in fleet_temoin; lesson 14.
Still open. Encryption on the wire stays with the servers in front; what crosses a shared disk is the programs' to check.
Cascading failuresOWASP ASI08
The threat. One runaway loop drags down everything around it.
The machine holds budgets in the kernel: past its memory a program is stopped, past its processor share it waits, past its task count it is refused. An update is a trial, kept only when every program is ready and the boot matches.
Seen in qemu_budget:
greedy (pid N) killed by signal 9; lesson 10.
Still open. The hardware watchdog's restart has not been seen on a board yet.Human–agent trust exploitationOWASP ASI09
The threat. The agent persuades a person to approve something harmful.
The machine turns every change into a new file, read as a difference, judged by the court before anything runs, tried once, and kept only if the machine recognises its own boot.
Seen in the court's 213 fixtures; lesson 5.
Still open. The tools for an agent to draft a change and a person to approve it are not built.
Rogue agentsOWASP ASI10
The threat. An agent turns on the machine it runs on.
The machine refuses every program the 25 calls of the floor. One not allowed to start others is alone in a process table of its own.
Seen in qemu_confine:
this world cannot change the machine it runs on; lesson 8.
Still open. The list is closed, never a claim that all else is safe; and a flaw in the kernel is a flaw in the walls.Next: A secure design → One machine, one program per role, and four ways to break its promises yourself.