The first question a security team asks an AI vendor: which OWASP risks do you cover, and how? Here is the risk-by-risk answer for the OWASP Top 10 for LLM Applications and the Top 10 for Agentic Applications — including where we stop.
Every row says what Cranium actually does about that risk, which moves of the AI Trust Loop do the work, and how deep the coverage goes. Detect & enforce means a documented detection plus an inline block or rewrite. Partial means real controls that don’t close the whole risk. Visibility means you’ll see it, fast. Where we don’t cover a risk, we say so.
The OWASP Top 10 for LLM Applications (2025 edition) is the list most security reviews start from. Cranium Guardian handles the runtime side — inspecting prompts and responses and acting on them inline — while Arena attacks your models before they ship and the AI‑BOM keeps the supply chain in view.
Crafted input rewrites what the model was told to do.
Guardian detects jailbreaks, instruction override, direct command injection, role impersonation and goal hijacking — and blocks or rewrites them inline. Arena attacks your models with injection and jailbreak suites before release, and agent config files are scanned for hidden instructions.
Models leak personal data, secrets or confidential content.
PII, PHI, PCI, secrets and named entities are detected in prompts and responses, then redacted or blocked by policy. Arena probes models for data leakage before they ship.
Third-party models, packages and vendors carry weaknesses into your stack.
The AI‑BOM inventories models, datasets, technologies and infrastructure from your repos, flags known CVEs and rescans on every push. AI Cards and Trust Hubs bring vendor AI under the same scrutiny.
Tampered training or fine-tuning data plants hidden behavior.
Cranium inventories the datasets behind each model, so you know exactly what feeds what. Detecting poisoned data itself is outside what Cranium does today.
Unchecked model output flows into code, queries or other systems.
Every response is evaluated before it leaves: code present, code vulnerabilities and sensitive data can be blocked or rewritten. Arena Shield tests output guardrails and exports NeMo-compatible config.
Agents hold more tools, permissions or autonomy than they need.
AgentSensor maps each agent’s tools, MCP servers and handoffs. At runtime, agent-to-tool traffic gets its own policy, Tool Inspector records every call, and an autonomy score shows how far agents run unsupervised. Granting or revoking agent permissions stays with your identity stack.
Hidden instructions and configuration get pulled out of the model.
Static system prompts are found and catalogued in the AI‑BOM. Guardian’s prompt-leaking signal catches extraction attempts at runtime, and Arena tests for it before release.
Retrieval stores and embeddings get poisoned, leaked or inverted.
Cranium does not inspect vector stores or retrieved context today.
Confident, wrong answers that people and systems act on.
Arena tests models for hallucination and misinformation before they ship. Runtime fact-checking is outside what Cranium does today.
Runaway usage drains budgets or degrades service.
Token, duration and cost analytics per use case and session show exactly where consumption spikes. Rate limiting stays with your gateway.
OWASP’s agentic list (December 2025) covers what changes when AI plans, calls tools, keeps memory and talks to other agents. Cranium evaluates each agent event type — user, LLM, tool, memory and agent-to-agent — under its own policy, and AgentSensor inventories the agents, tools and MCP servers behind them.
An attacker redirects what the agent is trying to achieve.
Guardian’s goal-hijacking and instruction-override signals run on every agent event type — user, LLM, tool, memory and agent-to-agent — and can block inline in Enforce mode.
Legitimate tools get used in unintended, harmful ways.
Tools are inventoried per agent from code. At runtime, agent-to-tool traffic has its own policy, every call lands in Tool Inspector, and top tool invocations are tracked. Content is policed; tool calls are not authorized or denied.
Agents inherit, escalate or misuse credentials and permissions.
Agent identity and privilege management sit outside Cranium today.
Compromised frameworks, tools, MCP servers or agent configs.
AgentSensor inventories frameworks, tools and MCP servers; agent config files are scanned for exfiltration endpoints, self-propagation and hidden Unicode; known CVEs are flagged on every rescan.
Agents generate or run code an attacker steered.
Code-requested, code-present and code-vulnerability signals plus direct-command-injection detection, with block or rewrite by policy.
Malicious content persists in agent memory and steers later steps.
Agent-to-memory reads and writes are their own event type with their own policy, so injection and sensitive-data signals run there too. There is no dedicated memory-poisoning detector today.
Messages between agents get spoofed, tampered or abused.
Handoffs are mapped from code; agent-to-agent and agent-initialized events are evaluated against policy at runtime, with multi-agent coordination tracked per session.
One bad step propagates across agents and systems.
Sessions rebuild multi-step, multi-agent workflows so you can see where in the chain a risk was introduced.
Agents manipulate the people who supervise them.
Not a documented Cranium capability today.
Agents drift from intended behavior or act outside scope.
Autonomy scores, agentic analytics and session flow make out-of-pattern agents visible fast. Stopping a rogue agent stays with your runbooks.
Mapping reflects documented Cranium capability as of October 2026 and is reviewed as OWASP revises its lists. Arena’s vulnerability categories link to their OWASP entries in the platform. OWASP is a registered trademark of the OWASP Foundation; Cranium is not affiliated with or endorsed by OWASP.
Most of the coverage above comes from three parts of Cranium ONE working the same loop.
Runtime inspection of prompts, responses and agent events, with block, modify or pass per signal — deterministic, explainable verdicts with Trace.
See ObserveFixed and adaptive attack suites — injection, jailbreaks, data leakage, misinformation and more — then guardrail testing you can export as config.
See SecureModels, datasets, agents, tools and MCP servers inventoried from your repos, with known vulnerabilities flagged on every rescan.
See DiscoverIn one working session we take your OWASP checklist, run it against your models and agents, and show you what Cranium covers — and what it doesn’t.
We use essential cookies to run this site, and — only with your permission — analytics and marketing cookies to improve it. You're the hero here; you stay in control. Privacy Policy.