Login Get a Demo
01 Frameworks · OWASP Top 10

The OWASP Top 10, mapped to the loop.

The first question a security team asks an AI vendor: which OWASP risks do you cover, and how? Here is the risk-by-risk answer for the OWASP Top 10 for LLM Applications and the Top 10 for Agentic Applications — including where we stop.

02 How to read this

Coverage you can check, not a logo wall.

Every row says what Cranium actually does about that risk, which moves of the AI Trust Loop do the work, and how deep the coverage goes. Detect & enforce means a documented detection plus an inline block or rewrite. Partial means real controls that don’t close the whole risk. Visibility means you’ll see it, fast. Where we don’t cover a risk, we say so.

03 OWASP Top 10 for LLM Applications

Ten LLM risks. Here’s where we stand.

The OWASP Top 10 for LLM Applications (2025 edition) is the list most security reviews start from. Cranium Guardian handles the runtime side — inspecting prompts and responses and acting on them inline — while Arena attacks your models before they ship and the AI‑BOM keeps the supply chain in view.

3Detect & enforce4Partial2Visibility1Not covered today
DOGSP Discover · Observe · Govern · Secure · Prove — the AI Trust Loop moves that address each risk
  1. LLM01

    Prompt Injection

    Crafted input rewrites what the model was told to do.

    Guardian detects jailbreaks, instruction override, direct command injection, role impersonation and goal hijacking — and blocks or rewrites them inline. Arena attacks your models with injection and jailbreak suites before release, and agent config files are scanned for hidden instructions.

    Detect & enforceDDiscoverOObserveGGovernSSecurePProve (no)
  2. LLM02

    Sensitive Information Disclosure

    Models leak personal data, secrets or confidential content.

    PII, PHI, PCI, secrets and named entities are detected in prompts and responses, then redacted or blocked by policy. Arena probes models for data leakage before they ship.

    Detect & enforceDDiscover (no)OObserveGGovernSSecurePProve (no)
  3. LLM03

    Supply Chain

    Third-party models, packages and vendors carry weaknesses into your stack.

    The AI‑BOM inventories models, datasets, technologies and infrastructure from your repos, flags known CVEs and rescans on every push. AI Cards and Trust Hubs bring vendor AI under the same scrutiny.

    PartialDDiscoverOObserve (no)GGovern (no)SSecure (no)PProve
  4. LLM04

    Data and Model Poisoning

    Tampered training or fine-tuning data plants hidden behavior.

    Cranium inventories the datasets behind each model, so you know exactly what feeds what. Detecting poisoned data itself is outside what Cranium does today.

    VisibilityDDiscoverOObserve (no)GGovern (no)SSecure (no)PProve (no)
  5. LLM05

    Improper Output Handling

    Unchecked model output flows into code, queries or other systems.

    Every response is evaluated before it leaves: code present, code vulnerabilities and sensitive data can be blocked or rewritten. Arena Shield tests output guardrails and exports NeMo-compatible config.

    PartialDDiscover (no)OObserveGGovernSSecurePProve (no)
  6. LLM06

    Excessive Agency

    Agents hold more tools, permissions or autonomy than they need.

    AgentSensor maps each agent’s tools, MCP servers and handoffs. At runtime, agent-to-tool traffic gets its own policy, Tool Inspector records every call, and an autonomy score shows how far agents run unsupervised. Granting or revoking agent permissions stays with your identity stack.

    PartialDDiscoverOObserveGGovernSSecurePProve (no)
  7. LLM07

    System Prompt Leakage

    Hidden instructions and configuration get pulled out of the model.

    Static system prompts are found and catalogued in the AI‑BOM. Guardian’s prompt-leaking signal catches extraction attempts at runtime, and Arena tests for it before release.

    Detect & enforceDDiscoverOObserveGGovernSSecurePProve (no)
  8. LLM08

    Vector and Embedding Weaknesses

    Retrieval stores and embeddings get poisoned, leaked or inverted.

    Cranium does not inspect vector stores or retrieved context today.

    Not covered todayDDiscover (no)OObserve (no)GGovern (no)SSecure (no)PProve (no)
  9. LLM09

    Misinformation

    Confident, wrong answers that people and systems act on.

    Arena tests models for hallucination and misinformation before they ship. Runtime fact-checking is outside what Cranium does today.

    PartialDDiscover (no)OObserve (no)GGovern (no)SSecurePProve (no)
  10. LLM10

    Unbounded Consumption

    Runaway usage drains budgets or degrades service.

    Token, duration and cost analytics per use case and session show exactly where consumption spikes. Rate limiting stays with your gateway.

    VisibilityDDiscover (no)OObserveGGovern (no)SSecure (no)PProve (no)
04 OWASP Top 10 for Agentic Applications

Agents get their own list. So do our answers.

OWASP’s agentic list (December 2025) covers what changes when AI plans, calls tools, keeps memory and talks to other agents. Cranium evaluates each agent event type — user, LLM, tool, memory and agent-to-agent — under its own policy, and AgentSensor inventories the agents, tools and MCP servers behind them.

1Detect & enforce5Partial2Visibility2Not covered today
DOGSP Discover · Observe · Govern · Secure · Prove — the AI Trust Loop moves that address each risk
  1. ASI01

    Agent Goal Hijack

    An attacker redirects what the agent is trying to achieve.

    Guardian’s goal-hijacking and instruction-override signals run on every agent event type — user, LLM, tool, memory and agent-to-agent — and can block inline in Enforce mode.

    Detect & enforceDDiscover (no)OObserveGGovernSSecurePProve (no)
  2. ASI02

    Tool Misuse & Exploitation

    Legitimate tools get used in unintended, harmful ways.

    Tools are inventoried per agent from code. At runtime, agent-to-tool traffic has its own policy, every call lands in Tool Inspector, and top tool invocations are tracked. Content is policed; tool calls are not authorized or denied.

    PartialDDiscoverOObserveGGovernSSecurePProve (no)
  3. ASI03

    Identity & Privilege Abuse

    Agents inherit, escalate or misuse credentials and permissions.

    Agent identity and privilege management sit outside Cranium today.

    Not covered todayDDiscover (no)OObserve (no)GGovern (no)SSecure (no)PProve (no)
  4. ASI04

    Agentic Supply Chain Vulnerabilities

    Compromised frameworks, tools, MCP servers or agent configs.

    AgentSensor inventories frameworks, tools and MCP servers; agent config files are scanned for exfiltration endpoints, self-propagation and hidden Unicode; known CVEs are flagged on every rescan.

    PartialDDiscoverOObserve (no)GGovern (no)SSecure (no)PProve
  5. ASI05

    Unexpected Code Execution

    Agents generate or run code an attacker steered.

    Code-requested, code-present and code-vulnerability signals plus direct-command-injection detection, with block or rewrite by policy.

    PartialDDiscover (no)OObserveGGovernSSecurePProve (no)
  6. ASI06

    Memory & Context Poisoning

    Malicious content persists in agent memory and steers later steps.

    Agent-to-memory reads and writes are their own event type with their own policy, so injection and sensitive-data signals run there too. There is no dedicated memory-poisoning detector today.

    PartialDDiscover (no)OObserveGGovernSSecurePProve (no)
  7. ASI07

    Insecure Inter-Agent Communication

    Messages between agents get spoofed, tampered or abused.

    Handoffs are mapped from code; agent-to-agent and agent-initialized events are evaluated against policy at runtime, with multi-agent coordination tracked per session.

    PartialDDiscoverOObserveGGovernSSecurePProve (no)
  8. ASI08

    Cascading Failures

    One bad step propagates across agents and systems.

    Sessions rebuild multi-step, multi-agent workflows so you can see where in the chain a risk was introduced.

    VisibilityDDiscover (no)OObserveGGovern (no)SSecure (no)PProve (no)
  9. ASI09

    Human-Agent Trust Exploitation

    Agents manipulate the people who supervise them.

    Not a documented Cranium capability today.

    Not covered todayDDiscover (no)OObserve (no)GGovern (no)SSecure (no)PProve (no)
  10. ASI10

    Rogue Agents

    Agents drift from intended behavior or act outside scope.

    Autonomy scores, agentic analytics and session flow make out-of-pattern agents visible fast. Stopping a rogue agent stays with your runbooks.

    VisibilityDDiscover (no)OObserveGGovern (no)SSecure (no)PProve (no)

Mapping reflects documented Cranium capability as of October 2026 and is reviewed as OWASP revises its lists. Arena’s vulnerability categories link to their OWASP entries in the platform. OWASP is a registered trademark of the OWASP Foundation; Cranium is not affiliated with or endorsed by OWASP.

05 Where it lives

Three engines behind the map.

Most of the coverage above comes from three parts of Cranium ONE working the same loop.

01

Cranium Guardian

Runtime inspection of prompts, responses and agent events, with block, modify or pass per signal — deterministic, explainable verdicts with Trace.

See Observe
02

Arena & Arena Shield

Fixed and adaptive attack suites — injection, jailbreaks, data leakage, misinformation and more — then guardrail testing you can export as config.

See Secure
03

AI‑BOM & AgentSensor

Models, datasets, agents, tools and MCP servers inventoried from your repos, with known vulnerabilities flagged on every rescan.

See Discover
06 Bring your security questionnaire

Walk the map
against your stack.

In one working session we take your OWASP checklist, run it against your models and agents, and show you what Cranium covers — and what it doesn’t.