OWASP Top 10 test
Test your agent against the OWASP Top 10 for LLMs
Every category on this page arrives carrying the framework identifiers the taxonomy holds for it, so a finding lands in the vocabulary your auditor already reads rather than in one only we use.
The mapping is in the taxonomy, not in the marketing
Every row here carries a severity and the identifiers the taxonomy holds for it. Not every category maps to both lists: Privilege Escalation is an Agentic entry, with no LLM number.
System Prompt Override
highThe agent ignores its system instructions and follows the attacker's instructions instead.
- LLM01:2025
- ASI01:2026
- AML.T0051.000
PII Leakage
criticalThe agent leaks personal data that was seeded into its context.
- LLM02:2025
- ASI06:2026
- AML.T0057
Excessive Agency
highThe agent takes actions beyond what was requested, without stopping to ask permission.
- LLM06:2025
- ASI02:2026
- AML.T0053
System Prompt Leakage
criticalThe agent reveals its system prompt or its hidden instructions.
- LLM07:2025
- ASI06:2026
- AML.T0056
- AML.T0069.002
Privilege Escalation
criticalThe agent grants elevated access or admin rights it should not.
- ASI03:2026
- AML.T0053
Free run
- One agent, one short security assessment
- Every finding with the attack that proved it
- Evidence for a reviewer, not a certification
Enoki platform
- Assessments that run far deeper
- The full conversation behind every finding
- Unlimited reruns
- Compliance workflows for the OWASP Agentic Top 10
Read further: What is AI red teaming?
The identifier is on the finding when it arrives
Enoki runs the mapped categories
Each one graded against its own published criterion.
Export findings already mapped
Each finding carries its OWASP and ATLAS identifiers, so it lands in the framework.
Questions before you run it
Which OWASP list does this cover, LLM or Agentic?
Both. Rows in the taxonomy carry LLM Top 10 identifiers for 2025 and Agentic identifiers for 2026, because an agent fails in ways the model list does not describe on its own.
Is this a compliance certification?
No. It produces mapped, reproducible evidence that a reviewer can read, which is a useful input to a compliance process and not a substitute for one.
Can I see the mapping before running anything?
Yes. The category table on this page is the mapping, taken from the same taxonomy file the attacker reads. Every finding in the report carries the mapping its category has in that file.
Other things Enoki will attack
Same free run, a different risk on each page.
- Prompt injectionInstructions hidden in what your agent reads.Test my agent for free →
- System prompt leakThe known paths to your agent's own rulebook.Test my prompt for free →
- Data leakageSecrets we hide, and whether they come back.Test my agent for free →
- JailbreaksMulti-turn attacks, not one-shot prompts.Test my guardrails for free →
- Agent pentestThe same attacks, on every release.Run the first one free →
Your first assessment
Enter your agent's endpoint
One field, no install, no code access. You get the report and the attack behind every finding.