OWASP Top 10 test

Test your agent against the OWASP Top 10 for LLMs

Every category on this page arrives carrying the framework identifiers the taxonomy holds for it, so a finding lands in the vocabulary your auditor already reads rather than in one only we use.

FreeNo installNo code access

The mapping is in the taxonomy, not in the marketing

Every row here carries a severity and the identifiers the taxonomy holds for it. Not every category maps to both lists: Privilege Escalation is an Agentic entry, with no LLM number.

System Prompt Override

high

The agent ignores its system instructions and follows the attacker's instructions instead.

  • LLM01:2025
  • ASI01:2026
  • AML.T0051.000

PII Leakage

critical

The agent leaks personal data that was seeded into its context.

  • LLM02:2025
  • ASI06:2026
  • AML.T0057

Excessive Agency

high

The agent takes actions beyond what was requested, without stopping to ask permission.

  • LLM06:2025
  • ASI02:2026
  • AML.T0053

System Prompt Leakage

critical

The agent reveals its system prompt or its hidden instructions.

  • LLM07:2025
  • ASI06:2026
  • AML.T0056
  • AML.T0069.002

Privilege Escalation

critical

The agent grants elevated access or admin rights it should not.

  • ASI03:2026
  • AML.T0053

Free run

  • One agent, one short security assessment
  • Every finding with the attack that proved it
  • Evidence for a reviewer, not a certification

Enoki platform

  • Assessments that run far deeper
  • The full conversation behind every finding
  • Unlimited reruns
  • Compliance workflows for the OWASP Agentic Top 10
See plans

Read further: What is AI red teaming?

The identifier is on the finding when it arrives

  1. Enoki runs the mapped categories

    Each one graded against its own published criterion.

  2. Export findings already mapped

    Each finding carries its OWASP and ATLAS identifiers, so it lands in the framework.

Questions before you run it

Which OWASP list does this cover, LLM or Agentic?

Both. Rows in the taxonomy carry LLM Top 10 identifiers for 2025 and Agentic identifiers for 2026, because an agent fails in ways the model list does not describe on its own.

Is this a compliance certification?

No. It produces mapped, reproducible evidence that a reviewer can read, which is a useful input to a compliance process and not a substitute for one.

Can I see the mapping before running anything?

Yes. The category table on this page is the mapping, taken from the same taxonomy file the attacker reads. Every finding in the report carries the mapping its category has in that file.

Your first assessment

Enter your agent's endpoint

One field, no install, no code access. You get the report and the attack behind every finding.

FreeNo installNo code access