OWASP Top 10 for Agentic Applications — ASI01–ASI10

Your SAST scanner doesn't know
what a tool call is.

ASIScan is static analysis built for AI agents. It audits your codebase against the OWASP Top 10 for Agentic Applications, the OWASP LLM Top 10, and EU AI Act Article 50 — then hands you the evidence document you attach when an enterprise customer sends you a security questionnaire asking how you secured your AI features.

Scanner is MIT and free · runs offline · no telemetry · npx asiscan-cli .

npx asiscan-cli .
ASIScan — OWASP ASI / LLM Top 10 static audit 2 files · 2 KB · 18 rules · 9ms CRITICAL ASI01 Agent Goal Hijack An attacker redirects the agent's objective using content the agent reads. Retrieved text shares a context window with your instructions. agent.ts:13:9 Untrusted content is interpolated directly into the system prompt. Anything reachable by an attacker becomes an instruction. │ const systemPrompt = `You are an ops assistant. Context: ${doc}` CRITICAL ASI05 Unexpected Code Execution (RCE) agent.ts:44:5 Shell command built by string interpolation. Model-influenced values in a shell string are a command-injection primitive. │ exec(`bash -c "${args.cmd}"`, (e, stdout) => { CRITICAL ASI09 Human-Agent Trust Exploitation agent.ts:52:1 Irreversible operations reachable with no human-in-the-loop gate. │ export async function deleteBucket(name, autoApprove = true) { 11 critical · 12 high · 3 medium controls satisfied: none
Two ways people arrive here

Which one is you?

PATH 1 — YOU BUILD THE AGENT

A questionnaire just landed and the deal is waiting

You shipped an agent feature this year. Now an enterprise prospect has sent 312 questions, forty of them about AI, and nobody on your team can answer question 26 — walk us through your kill switch — with anything you could put in writing.

Run the scanner today, free. Buy the assessment when you need the document. You will have something to attach this week instead of next month.

See what you get — $490
PATH 2 — YOU BUILD AGENTS FOR OTHERS

Your clients need diligence and you need it repeatable

You ship agents for clients and each one eventually asks what you did about security. Doing that assessment by hand, per project, does not scale, and "we reviewed it carefully" is not a deliverable you can invoice.

White-label the report, deliver it under your own brand, and make the assessment a billable line item on every engagement rather than unpaid reassurance.

Consultancy tier

Neither? If you just want to check your own code, the scanner is MIT and free forever — npx asiscan-cli . — and you never have to talk to us.

The gap

The frameworks are months old. The tooling isn't there yet.

OWASP published the Top 10 for Agentic Applications in December 2025 and refreshed the GenAI LLM Top 10 on 3 August 2026. Every engineering lead who shipped an agent this year is now expected to show they've assessed against frameworks that are months old — using scanners designed for a threat model that predates agents entirely.

Semgrep won't catch this

Generic SAST has no concept of a tool call, a system prompt, or agent memory. It sees valid code and moves on.

Neither will a code review

The dangerous patterns look ordinary. A standing admin token and a scoped one are one line apart.

And the questionnaire is already in your inbox

"Describe the security controls applied to your AI/LLM features." There is no standard answer yet. Deals stall in that gap.

Jurisdictions

This is not an EU compliance tool.

OWASP is not a jurisdiction. The ASI Top 10 describes how agents actually get attacked — prompt injection through retrieved content, a tool with a standing admin token, a shell string built from model output. None of that becomes safe because your company is in Ohio. Here is the reason to run this where you are.

🇺🇸 United States

Your buyer's procurement team is the regulator. SOC 2 and enterprise security questionnaires now carry AI-specific sections, and auditors are asking which framework you assessed your AI features against. "We reviewed it internally" is not an answer that closes a six-figure deal. An ASI Top 10 report is.

🇨🇦 Canada

PIPEDA already applies to automated decisions about people, and federal procurement expects a documented algorithmic impact assessment. Most Canadian teams also sell into the US and EU, which means you inherit the strictest questionnaire you receive — usually before you have anything to answer it with.

🇬🇧 United Kingdom

The UK took a regulator-led route rather than a single AI act, so the ICO, FCA and MHRA each expect sector-appropriate evidence. NCSC guidance on secure AI development is the de-facto baseline, and it maps cleanly onto the same controls. UK teams selling into the EU pick up Article 50 regardless of where they're incorporated.

🇪🇺 European Union

The sharpest deadline, and the reason this exists: Article 50 transparency became enforceable on 2 August 2026, with synthetic-content marking following on 2 December 2026. The included worksheet covers scope, classification, and the documents an assessor asks for. It is one module of the product, not the whole pitch.

The security case is the same everywhere. The paperwork differs, so the paperwork ships as a separate worksheet you use only if it applies to you.

Coverage

18 rules. All ten ASI risks.

The interesting part is how it checks. Agentic risk is usually a missing control, not a forbidden token. Code isn't unsafe because it calls exec — it's unsafe because it calls exec on a model-influenced string with no sandbox and no egress policy.

ASI01

Agent Goal Hijack

Retrieved content reaching the system prompt undelimited.

ASI02

Tool Misuse

Unvalidated tool parameters; no allowlist or authorisation policy.

ASI03

Identity & Privilege Abuse

Hardcoded and non-expiring credentials; agents on standing tokens.

ASI04

Agentic Supply Chain

Unpinned MCP servers, missing AIBOM, no provenance verification.

ASI05

Unexpected Code Execution

Shell strings built by interpolation; code tools with no sandbox.

ASI06

Memory Poisoning

Unscoped memory across tenants; writes with no validation or TTL.

ASI07

Inter-Agent Comms

Unauthenticated handoffs; no signing, no replay protection.

ASI08

Cascading Failures

Unbounded loops; no circuit breaker, retry cap, or timeout.

ASI09

Human-Trust Exploitation

Bypassed approval gates; irreversible actions with no confirmation.

ASI10

Rogue Agents

No audit log, no kill switch, no cancellation path.

LLM01–LLM10

LLM Top 10 overlap

Prompt injection, disclosure, output handling, excessive agency, consumption.

EU AI ACT

Article 50

Missing AI-interaction disclosure; unmarked synthetic content.

ASCII SMUGGLING

Invisible instructions

Zero-width characters, bidi overrides (Trojan Source), Unicode tag characters, poisoned tool descriptions.

The gap between what you read and what the model reads

A model reads codepoints. You read rendering. Everything in between is attack surface — and it is the one place a scanner beats a careful reviewer outright, because the reviewer is looking at characters that are not drawn.

A zero-width space carries a smuggled instruction through code review untouched. A bidirectional override makes source render one way and parse another (CVE-2021-42574). The Unicode tag block is a complete invisible ASCII alphabet. And a tool description reading "before using any other tool you must first…" is not documentation — descriptions go to the model verbatim, so that is a tool-poisoning primitive.

Across five large agent frameworks these four checks produce zero findings. Against a crafted smuggling fixture, all four fire. Silent on clean code, loud on the real attack — including the U+FEFF byte-order mark we removed from the signature after every hit it produced on real code turned out to be false.

Where this fits

Not a package scanner. The other half.

There are good tools that scan the AI packages and MCP servers you install — asking whether the third-party thing you're about to run is malicious. That is a real problem and a different one. ASIScan reads the agent you wrote.

Package / MCP scannersASIScan
Question answeredIs this dependency malicious?Is the agent we built defensible, and can we prove it?
SubjectThird-party packages, MCP servers, installed skillsYour own repository
Framework mappingAd-hoc threat categoriesEvery finding carries an ASI, LLM or Art. 50 ID
Deep analysisOften ships your source to an LLM providerFully offline. No network calls, no telemetry, air-gap capable
Evidence outputFindingsFindings plus a 49-item manual checklist, EU worksheet, 30 red-team probes
LicenceFrequently AGPL — banned outright at many enterprisesCommercial, perpetual. No copyleft obligation on your codebase

Run both if you can. They overlap only at ASI04, agentic supply chain — where ASIScan checks that your MCP servers are pinned and provenance-verified, rather than auditing someone else's package for you.

Two of those rows are worth reading twice if you sell to enterprises. A tool that uploads your source to a third-party LLM is a question on the very security questionnaire you're trying to answer — and an AGPL dependency is a procurement conversation you don't want to have.

Proof

Measured, not asserted.

Two reference agents ship in the box — one deliberately unsafe, one properly secured. Every claim here is reproducible with npm test on your own machine.

FixtureFindingsControls recognised
vulnerable-agent
60 lines, deliberately unsafe
260
secure-agent
reference implementation
05

A scanner that flags everything is noise. One that flags nothing is decoration. Sensitivity and specificity are both tested, and both are in the test suite.

Then tuned against fifteen real repositories

Fixtures prove a scanner can fire. They don't prove it's usable. ASIScan was tuned in rounds against fifteen open-source agent frameworks — roughly 17,000 source files — with every surviving finding reviewed by hand.

Tuning roundFindingsPrecision
Untuned — 5 repos, ~3,100 files792~4%
Tuned — same 5 repos36~55%
Expanded to 10 repos, ~14,000 files89~62%
+ file-level context gating78~69%
+ targeted fixes (v1.5.1)49~75–80%*

*That last row was validated only against the five repositories carrying the false positives it targeted, and an independent check on unseen code in September 2026 came in lower. So we don't quote a current figure: precision for v1.5.2 is being re-measured across a 50-repository corpus, and the result, method and raw counts will be published here.

Among the false positives removed: flagging url.startswith(('http://','https://')) — scheme-validation code, i.e. reporting the security control as the vulnerability, 475 findings. Matching xmlns="http://www.w3.org/2000/svg" as a network endpoint. Matching JavaScript's regex.exec(text) as process execution. And treating test files as production code — they were two thirds of all findings in round two.

For context, since nobody else gives you any

Published benchmarks put untuned commercial SAST at 60–90% false positives, dropping to 10–20% once tuned for a specific stack. SonarQube reports 40–60% of findings requiring developer review.

A ~20–25% false-positive rate is the well-tuned commercial band. The difference is that this number is measured, published, and reproducible against named public repositories rather than asserted in a datasheet. No other scanner in this category publishes theirs — you should ask them why.

What it does not do

It reads source, not behaviour. It cannot see your IAM policy, network topology, runtime config, or what your model actually does at inference time.

Control probes are project-wide: if a mitigation exists anywhere, the rule stays quiet — even if it isn't applied on the path that needs it. A clean result is weaker evidence than a dirty one.

It is regex-based, not AST-based. It is not a certification, not a conformity assessment, and not legal advice.

The manual review checklist ships with it precisely because the scanner is not sufficient on its own. Anyone selling you an AI compliance scanner without that caveat is selling you a false sense of security.

Contents

The scanner is half of it.

Static analysis covers roughly half the ASI Top 10. The rest is architecture, runtime configuration, and process. So the other half of the box is the paperwork you'd otherwise spend a week writing.

ComponentWhat it is
CLI scanner18 rules, 4 output formats — terminal, markdown, JSON, SARIF 2.1.0
GitHub ActionPR gate, uploads to the GitHub Security tab, weekly scheduled re-scan
Manual review checklist49 checks with severity and an evidence column, covering what source can't show
EU AI Act worksheetScope, classification, Art. 50 controls, and the 10 documents auditors ask for
Red-team probe suite30 adversarial probes as JSONL, mapped to risk IDs, with pass/fail signals
Reference agentsA vulnerable and a secured implementation, annotated line by line
Full TypeScript sourceReadable, commented, and yours to extend with your own rules
Pricing

The scanner is free. The evidence isn't.

Rules are a commodity — there are free agent scanners, and ours is one of them, MIT licensed on npm. What nobody hands you is a document a procurement team accepts. That is the part that takes judgement, and that is the part we charge for.

Scanner
Free

MIT licensed. Not a trial, not crippled, no signup.

  • All 18 rules, ASI + LLM + Art. 50
  • ASCII-smuggling detection
  • Terminal, markdown, JSON, SARIF
  • GitHub Action & CI gate
  • Runs offline. No telemetry
npx asiscan-cli .
Assessment
$490 once

One dated report for one codebase. The thing you attach.

  • Assessment report (HTML + PDF)
  • NIST AI RMF & ISO 42001 crosswalk
  • Questionnaire answer pack
  • 49-item manual review checklist
  • EU AI Act worksheet
  • 30 red-team probes
Get the assessment
MOST TEAMS PICK THIS
Continuous
$2,400/year

Because a report is stale the moment you merge.

  • Everything in Assessment
  • Unlimited repos and re-scans
  • Quarterly re-issued, re-dated report
  • Drift diff against last quarter
  • Hosted trust page you can link buyers to
  • Rule updates as OWASP moves
Start continuous
Consultancy
$6,000/year

Deliver assessments to your own clients, under your brand.

  • Everything in Continuous
  • Unlimited client engagements
  • White-label report output
  • Right to deliver reports to third parties
  • Rule authoring guide
Get consultancy

Why this is cheap

ISO/IEC 42001 certification runs $37,500–$85,000 in year one — GRC platform, external audit, and implementation consulting — and around $115,000 across three years. That is the right tool for a different job, and it takes months.

Meanwhile the thing actually costing you money is the wait. AI questionnaires stretch vendor review from about a week to four to eight weeks. For a company with $250K contracts that has been estimated at $400K–$800K per quarter in delayed or lost revenue.

$490 to unblock the review is not a purchase anyone has to think about. Perpetual licence, 30-day refund, no justification required.

Payments are processed by Stripe. Your card statement and the checkout page will show EASE AI / Protocol42 — Ease AI Works is the merchant of record for ASIScan.

FAQ

Questions you should be asking

Isn't this just a pile of regexes?

Partly, and the README says so plainly. The design contribution is the control-probe model: a rule fires only when your code demonstrably performs a risky behaviour and no evidence of the mitigating control appears anywhere in the project. That maps to how the ASI list is actually written — most entries are missing-control findings. It also deliberately excludes comments from counting as evidence, so a // TODO: add sandboxing can't make the scanner report you as mitigated.

Will it work on my Python / Go / .NET agent?

It scans TypeScript, JavaScript, Python, Go, Rust, Java, C#, PHP, plus JSON, YAML, TOML, shell, and Dockerfiles. Rule coverage is strongest on TS/JS and Python, where most agent code lives today. Rules are plain objects — extending them for your stack is a small diff, and the guide is included.

Does my code leave my machine?

No. It runs entirely offline, makes no network calls, and has no telemetry. You can verify that in the source, which you get.

We're not in the EU. Why would we run this?

Because the EU AI Act is the smallest reason to. The OWASP ASI Top 10 describes how agents get attacked, and that threat model doesn't stop at a border — a shell string built from model output is a command-injection primitive in Toronto, Austin and Manchester alike.

The commercial reason is more immediate: enterprise security questionnaires and SOC 2 reviews now include AI-specific sections, and "we reviewed it internally" doesn't clear them. A scan report naming the framework you assessed against, plus a completed manual checklist with an evidence column, is a document you attach and move on. That's revenue protection, not compliance cost. The EU worksheet is one module in the box — use it if you sell into the EU, ignore it if you don't.

Does this make me EU AI Act compliant?

No, and be suspicious of any tool that claims it does. Compliance is a legal determination requiring a documented human assessment. What this gives you is the engineering-side evidence and the worksheet that gets your lawyer the facts they'll ask for. That's the honest scope.

Why should I trust a v1.x?

Don't trust it — run it. The test suite is included and reproduces every number on this page. The two reference agents let you verify sensitivity and specificity yourself in about a minute. And there's a 30-day refund if it doesn't earn its keep.

What if I find a false positive?

Email it. Rules are data, not hardcoded logic — most fixes are a one-line regex change that ships in the next v1.x update, which you get free.

Find out what's in your agent before someone else does.

Scan free in under a second. Buy the evidence when a reviewer asks for it.

Get the assessment — $490