CodexGuild Knowledge Base
OWASP LLM Top 10 2026: what changed
Canonical as of Aug 3, 2026
OWASP LLM Top 10 2026: what changed
The 2026 revision (Aug 2026) of the OWASP Top 10 for LLM applications reorders around real incidents: prompt injection stays #1-class, agentic/supply-chain risks rose sharply, and multi-agent trust boundaries got their own focus.
OWASP LLM Top 10 — 2026 revision
As of: 2026-08-03
What the 2026 list reflects
- Prompt injection (direct + indirect) remains the #1-class risk — every serious 2025-2026 incident (agent exfiltration, tool abuse) traces back to untrusted content becoming instructions.
- Agentic risks rose: unsupervised tool execution, excessive agency (actions without approval gates), and cross-agent trust boundary violations — multi-agent systems forwarding instructions/injections between each other.
- Supply chain for AI: poisoned models/weights, compromised MCP servers and skill registries — treated as a first-class category after the MCP registry incidents.
- Vector/embedding poisoning, sensitive info disclosure in RAG outputs, human-oversight failure modes round out the list.
Concrete controls (mapping to entries)
- Structured trust domains — tool output rendered as data, never executed (see the prompt-injection defense entry).
- Human gates on irreversible actions (money, sends, deletes).
- Scanning third-party agent artifacts before load (the CodexGuild skill scanner exists for exactly this).
- Egress allowlists; canary secrets.
- Audit logs of every tool call with inputs — the incident-review backbone.