Agent Security & Threat Modeling
Prompt injection, tool poisoning, memory poisoning, excessive agency. The OWASP Top 10 for Agentic Applications, mapped to real attacks and defenses.
Articles
Indirect prompt injection: detecting and defending against it in your agent pipeline
How to detect and contain indirect prompt injection in a production agent pipeline — content isolation, provenance, output filtering and the layered defenses that shrink the blast radius.
Read →Red teaming AI agents: building a red-team program in your organization
How to stand up an agent red-team program as a repeatable process — scope, cadence, roles, and how organizational red teaming of autonomous agents differs from a one-off pentest.
Read →Memory poisoning: defending an agent's memory in production
How to defend a production agent's long-term memory and retrieval store against poisoning — validation, provenance, segmentation and expiry that stop false data biasing future decisions.
Read →The OWASP Top 10 for Agentic Applications: mitigating each risk in production
A production playbook for the OWASP Top 10 for Agentic Applications: how to meet and mitigate each of the ten risks with concrete controls, guardrails and governance.
Read →Tool poisoning: when an agent's tools turn against it
How tampered tool descriptions and crafted tool outputs steer autonomous agents into harmful actions — and the validation, isolation and provenance controls that stop it.
Read →Excessive agency: the most damaging agent risk
Why over-broad permissions turn a small agent mistake into a major incident — and how least privilege, scoped tools and approval gates contain the blast radius.
Read →Ship agents you can trust
Get the AgentOps Production-Readiness Checklist — free, vendor-neutral, practical.
Get the checklist