PRIMARYOWASP Top 10 for Agentic Applications 2026 — ASI04: Agentic Supply Chain Vulnerabilities
OWASP Foundation · 2026 · owasp.org
Authoritative source for the official definition of ASI04, the six vulnerability types (poisoned prompt templates, tool-descriptor injection, impersonation/typosquatting, vulnerable third-party agents, compromised MCP/registry servers, poisoned knowledge plugins), the six attack scenarios, and the nine mitigation categories. The OWASP PDF is the canonical source for the distinction between static and dynamic supply chain attack surfaces, and for the "live supply chain" characterization of agentic ecosystems. Used throughout this module.