資料來源#
摘要#
Open Worldwide Application Security Project 是一個歷史悠久的非營利安全社群,過去以 OWASP Top 10 網頁應用程式風險聞名。在代理式時代,它是建構 Zero Trust for AI Agents 架構的威脅分類來源、創造了 Least Agency 一詞(將最小權限原則延伸至代理程式),並維護用於供應鏈透明度的 AI-BOM 標準。
OWASP 對代理式安全的貢獻#
- 代理式威脅分類 — 架構的第二部分(「代理式系統的當前威脅」)依據 OWASP 指出的威脅編排: prompt injection、工具與資源劫持、身分與存取權限濫用、記憶與上下文中毒,以及供應鏈風險。
- 「least agency」 — OWASP 創造的詞,將最小權限原則延伸至代理式應用程式,限制每項代理工具能做什麼、使用頻率,以及可作用的範圍。參見 Least Agency。
- AI-BOM — OWASP 的 AI 軟體物料清單,是其 CycloneDX ML-BOM 的延伸版本,並以網頁工具形式提供。它追蹤模型來源、訓練資料集脈絡,以及微調參數;該架構建議將它與 OpenSSF Scorecard 一起整合,讓模型與程式碼相依項目帶有相同的風險訊號。
與其他標準組織的關係#
在 Zero Trust 的脈絡中,OWASP 與該架構引用的正式政府標準並列:NIST(SP 800-207)、NSA(Zero Trust Implementation Guides)、CISA(Zero Trust Maturity Model),以及英國 NCSC、Australia Home Affairs 等國際組織。OWASP 提供應用程式/代理層級的威脅詞彙;政府組織則提供架構層級的原則。
延伸閱讀#
- Zero Trust for AI Agents — 以 OWASP 代理式威脅分類為基礎的架構
- Least Agency — OWASP 創造的詞
- Agent Supply Chain Risk — OWASP 維護用於管理供應鏈風險的 AI-BOM
- Agentic Prompt Injection/Memory and Context Poisoning — OWASP 代理式威脅分類中的威脅
- Anthropic — 在其 Zero Trust 架構中採用並擴充 OWASP 分類
資料來源#
- Zero Trust for AI Agents — 該文件引用 OWASP 作為代理式威脅分類、「least agency」一詞與 AI-BOM 的來源
Cited by 14
- Agentic Prompt Injection×2
Prompt injection is the insertion of malicious instructions that cause an agent to follow attacker…
- Guarantees That Degrade at Deployment: Action-Space Soundness, Admissibility Without Effect, and a Vendor-Coupled Security Framework×2
Concept pages: Reasoning Acting Interleaving, Continuous Self Modification Under Review, Zero Trust…
- Least Agency×2
Least agency is a term coined by Owasp that extends the classic least-privilege principle to…
- Security Debt of Agent-Generated Code×2
Six categories grounded in OWASP secure-coding guidance (Owasp), the CIS Benchmarks, and GitHub…
- Zero Trust for AI Agents×2
The framework treats every Claude Code "Pro-tip" as a reference implementation. How much of the…
- Agent Data Injection (ADI)
Owasp — ADI is a new subcategory under the OWASP LLM01 prompt-injection umbrella
- Agent Supply Chain Risk
Owasp — supply chain in the agentic threat taxonomy; maintains the AI-BOM
- Anthropic
Owasp — Anthropic adopts and extends OWASP's agentic threat taxonomy and "least agency" term in the…
- Capability Gating Is Not Authorization
Owasp — the confused-deputy failure is indirect prompt injection under OWASP LLM01 (and MITRE ATLAS…
- MCP Tool Poisoning
Owasp — TPA sits under the OWASP LLM01 indirect-prompt-injection umbrella; Agentjacking is…
- Entities — People, Orgs, Tools & Projects
Owasp — Open Worldwide Application Security Project; source of the agentic threat taxonomy cited…
- Open Questions Dashboard
Zero Trust For Ai Agents: The framework treats every Claude Code "Pro-tip" as a reference…
- Out-of-Band Prompt-Injection Defense
Owasp — the paper builds on OWASP's LLM01:2025 framing and its note that a guardrail model is…
- Self-Propagating Prompt Injection (AI Worms)
Owasp — the source classes the attack as an XPIA under the OWASP LLM01 prompt-injection umbrella
Related articles
- Agent Data Injection (ADI)
A new category of indirect prompt injection: malicious payloads disguised as *trusted data* (metadata like a comment's…
- Zero Trust for AI Agents
Anthropic's security framework for deploying autonomous agents: trust nothing / verify everything / assume breach, appl…
- Write-Then-Trusted
The seam where sandboxed agents escape without breaking anything: the agent writes a file it is fully permitted to writ…
- Agentic Prompt Injection
Direct and indirect injection of malicious instructions into an agent; LLMs cannot reliably distinguish information fro…
- Observability-Pipeline Poisoning
The observability stack — WAF blocks, APM logs, error-tracker events — is an attacker-writable input channel that agent…
