The OWASP Top 10 for Agentic Applications is the OWASP GenAI Security Project’s list of the ten highest-impact security risks for AI agents. This checklist puts each one beside the control Insulin’s documentation describes and what that documentation doesn’t promise. It is Fours’ reading of its own docs, not OWASP’s assessment.
If an AI-vendor security review asks how a product maps to the OWASP Top 10 for Agentic Applications for 2026, a list of controls is only half an answer. Every control stops somewhere, and the reviewer needs to know where.
So each of the ten risks gets one row below: what the risk looks like in an AI workspace, the control Insulin’s documentation describes, and what that documentation doesn’t promise. Every control and every limit comes from the live Insulin and integration documentation, quoted where the wording matters. OWASP has not reviewed this table, no row claims a risk is solved, and nothing here is a certification.
What is the OWASP Top 10 for Agentic Applications?
The OWASP Top 10 for Agentic Applications is the OWASP GenAI Security Project’s list of the ten highest-impact security risks for agentic AI, numbered ASI01 to ASI10. Version 2026 was published in December 2025 by the project’s Agentic Security Initiative, as a PDF you can download from OWASP.
It is written for agents that “plan, decide, and act across multiple steps and systems”, and each entry gives a description, common examples, attack scenarios and prevention guidelines. OWASP calls the list “a compass and go-to reference” for security leaders and practitioners. Two ideas run through all ten entries: least agency, OWASP’s advice to “avoid unnecessary autonomy”, and observability, which it calls “non-negotiable”.
The table below uses the ten titles exactly as the 2026 PDF prints them, so a reviewer can match each row to OWASP’s own entry.
How does Insulin map to each OWASP agentic risk?
Row by row: the risk, what it looks like in an AI workspace, the control Insulin’s documentation describes, and what that documentation doesn’t promise. The second column paraphrases OWASP’s own description of the risk. The third and fourth come from Insulin’s documentation, and the linked post in each row explains that control in full.
| OWASP risk | What it looks like in an AI workspace | What Insulin’s docs describe | What the docs don’t promise |
|---|---|---|---|
| ASI01: Agent Goal Hijack | Instructions hidden in what the agent reads, such as an email, a document or a web page, redirect its goal, because the model can’t reliably tell instructions from content | Inbox’s Text the AI read line on every HTML email, with a warning when the plain text holds about twenty words or more that the visible email doesn’t show; auto-send rules that fire on one exact filter and get no outside context; goal objectives only your steer can amend | The hidden-text check “never blocks anything”. It decides only how prominently the text is shown, so reading it before you approve is up to you |
| ASI02: Tool Misuse and Exploitation | An agent uses a tool it is allowed to use in an unsafe way: writing or deleting where it should only read, calling costly tools over and over, or sending data out | A per-agent integration allowlist; knowledge bases in Read or Edit mode, never delete; an Inbox CRM action run limited to the CRM connection it came from; Access levels on Fours’ own MCP server card, Read only by default; a Tool Approval Required card on some tool calls | The approval card is offered only “in an interactive solo chat in the web workspace, on the main thread”, so a channel, a Slack or Teams DM or a sub-thread doesn’t hold the action back. The allowlist picks systems, not tools, and other MCP servers “expose whatever tools they offer” |
| ASI03: Identity and Privilege Abuse | The credentials and delegated access an agent acts with let it reach more than its task, or the person asking, should | Organization agents limited to organization-level integrations, user-level agents to user-level ones; Planner, the organization-channel coordinator, with no integrations and no personal data; jobs that run within their creator’s scope; the credential behind each connection as the ceiling | An organization connection is one identity for everyone who uses it. On Zuora, “Every Fours user in your organization shares the org connection”; on Ironclad, the acting user “is fixed at connect time and applies to every request, for everyone in your organization” |
| ASI04: Agentic Supply Chain Vulnerabilities | Third-party pieces the agent loads at runtime, such as skills, tools, MCP servers or prompt templates, arrive malicious or tampered with and bring hidden instructions or unsafe code | Skills from upload, GitHub import or SkillsMP, each card showing a provenance badge; Enable/Disable on every skill; Organization-store imports, edits and deletes limited to org admins | A .zip package, whose scripts are kept for runtime loading, “imports directly, no review step”; GitHub repo, folder and blob URLs “import the full package directly, preserving referenced files”. The docs describe no scan of what comes in |
| ASI05: Unexpected Code Execution (RCE) | Code the agent writes or is handed gets steered into running an attacker’s commands, ending in a compromised host or container, or a sandbox escape | An organization sandbox pool, provisioned when an organization-owned agent first runs a job and managed on an org-admin-only Sandboxes tab with Start, Stop, Destroy and Auto-stop; job filters in “a safe, sandboxed expression language” | How a sandbox is isolated, from other sandboxes, from the network or from the rest of the platform, isn’t described. Ask |
| ASI06: Memory & Context Poisoning | False or planted content gets into what the agent remembers or retrieves, such as long-term memory or a knowledge base, and skews its answers in later sessions | A memory recall indicator; Settings → Personal → Memory to search, edit or delete memories, or Clear All; corrections in place when you tell the Insulin assistant; confidence that decays without reinforcement; deprecated knowledge-base files that a sync won’t bring back into search | Memories shared across your organization are listed, but “their Edit and Delete buttons are disabled”. Nothing like Inbox’s hidden-text check is described for knowledge-base documents or memories |
| ASI07: Insecure Inter-Agent Communication | Messages between agents are intercepted, spoofed, tampered with or replayed when the exchange lacks authentication or integrity checks | An adjacent control, not an answer: in an organization channel, only Planner delegates, and specialists never hand off to each other | The docs say who may delegate, not how messages between agents are authenticated or protected. In a personal channel, specialist agents can hand off to each other |
| ASI08: Cascading Failures | One fault, such as a bad output, a failing model or poisoned context, spreads across agents, runs and workflows and multiplies through fan-out and retry loops | Failover named in the reply; usage-limit cards; automatic job runs capped at 60 an hour per job and 300 an hour per organization, with one run in flight per job; no Retry on a failed CRM action run | In a channel, one agent that can’t get a model stops the whole turn, and “none of the channel’s other agents answer it”. Job rate limits “are fixed — there is no setting for them”, a manual job’s Run skips them, and Run now bypasses the enabled check |
| ASI09: Human-Agent Trust Exploitation | A person approves an agent’s confident draft or proposed change without checking what it rests on, so a manipulated agent gets a human to take the final, irreversible step | A two-step Send, because “sending is irreversible”; the evidence on the reply pane, including the Customer block and Text the AI read; a CRM action record that keeps receipt and outcome apart and shows outcome not recorded “rather than a fabricated success” | The evidence is shown, not verified: the Customer block is “a snapshot … not today’s figures”, and the hidden-text warning changes only how prominently text is shown. Channels, Slack or Teams DMs and sub-threads never pause for approval |
| ASI10: Rogue Agents | An agent drifts from its intended function or scope and keeps acting, each step looking legitimate, so containment depends on who can see it and stop it | A stop control for each surface: Stop, Cancel goal, Terminate or Disable, and a switch on every Inbox rule; job Steps transcripts kept even when a run fails; a CSV export from Approvals ▸ History; agent deletion limited to the owner; no org-wide ADMIN share | An org admin can’t see or stop another member’s job: a job is private to its owner, admins included. The organization-wide brake the docs describe is the monthly spending limit, which “Pauses AI requests for the rest of the month” |
Which rows depend on settings your organization owns?
Most of them. Insulin’s documentation describes each control, but your organization decides how it is set:
- Each agent’s integration allowlist and knowledge-base modes (ASI02). Grant only the systems the agent’s job needs, and attach a knowledge base in Edit mode only when the agent should maintain it. On an organization agent, only an org admin can change the integrations.
- The credential behind each organization connection (ASI03). That identity’s permissions are the ceiling on what the agent can do, and the Ironclad and ServiceNow pages both advise a dedicated integration user rather than a real employee’s account.
- Who holds org admin (ASI03, ASI04). Only org admins create organization agents and channels, connect organization integrations, and import or edit skills in the Organization store.
- Auto-send rules in Inbox (ASI01). Insulin sends mail without review only through an auto-send rule you wrote yourself on the Rules page; the Inbox chat rail refuses to create one.
- The monthly spending limit (ASI08, ASI10). Set on Settings → Billing, it pauses AI requests for every member at once.
The rest of the fourth column lists documented limits, not settings. Write them into the review as they stand: the approval card’s single surface, for instance, is a fact about the product rather than a configuration someone missed.
What should you ask Fours that the docs don’t answer?
Two rows rest on behaviour the documentation doesn’t describe: how a sandbox is isolated (ASI05), and how messages between agents are authenticated and protected (ASI07). A third question follows from ASI04. Put all three to Fours in writing:
- How is an organization sandbox isolated from other sandboxes, from the network and from the rest of the platform? The documentation says where sandboxes come from and who manages them, not how they are contained.
- How are messages between agents in a channel authenticated and protected against tampering and replay? The documentation says who may delegate, which sits next to OWASP’s concern rather than answering it.
- Is an imported skill package checked before agents can load it? The documentation describes provenance badges and an org-admin gate on the Organization store, and no review step for a
.zippackage or a GitHub folder.
Ask for each answer as something you can file with the review, so it can sit in this table beside the rows the documentation already answers.
Frequently asked questions
Is this checklist an OWASP assessment of Insulin?
No. It is Fours’ reading of Insulin’s own documentation against OWASP’s list, not an OWASP review, and it makes no certification claim. Each row names the control the documentation describes and what the documentation doesn’t promise, so a reviewer can check both.
What are the ten risks in the OWASP Top 10 for Agentic Applications?
They are ASI01: Agent Goal Hijack; ASI02: Tool Misuse and Exploitation; ASI03: Identity and Privilege Abuse; ASI04: Agentic Supply Chain Vulnerabilities; ASI05: Unexpected Code Execution (RCE); ASI06: Memory & Context Poisoning; ASI07: Insecure Inter-Agent Communication; ASI08: Cascading Failures; ASI09: Human-Agent Trust Exploitation; and ASI10: Rogue Agents.
Does an Insulin agent always ask before it acts?
No. Some tool calls pause on a Tool Approval Required card, but the card is offered only in an interactive solo chat in the web workspace, on the main thread. In a channel, a Slack or Microsoft Teams DM, or a sub-thread, the turn proceeds without pausing.
Can an organization admin stop another member’s job?
No. A job is private to its owner, organization administrators included. One brake does reach every member: the monthly spending limit on Settings → Billing. Set below what the organization has spent this month, it pauses AI requests for the rest of the month.
Does Insulin block prompt injection hidden in an email?
No. In Inbox, every HTML message carries a “Text the AI read” line, and a message whose plain text holds a passage of about twenty words or more that the visible email doesn’t show gets a warning in its place. The check never blocks anything.
Which OWASP agentic risks do Insulin’s docs say least about?
ASI05 and ASI07. The documentation describes organization sandboxes and who may delegate in a channel, but not how a sandbox is isolated or how messages between agents are authenticated and protected. Put both to Fours as questions in your review.
Takeaways
- The 2026 list has ten risks, ASI01 to ASI10, published by the OWASP GenAI Security Project in December 2025. Quote the titles as its PDF prints them.
- Read each row as a pair: the control Insulin’s documentation describes, and what that documentation doesn’t promise. This is Fours’ reading of its own docs, not an OWASP assessment.
- The approval card guards one surface. A channel, a Slack or Teams DM and a sub-thread never pause, so scope agents with allowlists and narrow credentials instead of counting on a pause.
- An organization connection is one identity for everyone who uses it, so choose the credential behind it deliberately: a dedicated integration user with narrow roles.
- Ask Fours about the two silent rows: sandbox isolation (ASI05) and how messages between agents are protected (ASI07).
OWASP’s list names the agentic risks; a vendor review asks about more than that. Take this table into your next review alongside the 25 security questions to ask an enterprise AI agent vendor, which run from data and access through audit and deletion.
Sources
Primary sources for the platform rules cited above. Last verified October 8, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.
- Insulin Inbox — Fours Doc — The Text the AI read line on every HTML message, and its warning when the plain text holds a passage of about twenty words or more that the visible email doesn't show, a check that never blocks anything; an auto-send rule's one exact filter, no outside context and pre-send check; Send as a two-step gesture because sending is irreversible; the reply pane's evidence and the Customer block as a snapshot, not today's figures; a CRM action run limited to the one CRM connection it came from, with no Retry on failure; the receipt and outcome in Approvals ▸ History, outcome not recorded rather than a fabricated success, and its CSV export; an enable switch on every rule, and auto-send rules written only on the Rules page
- Insulin Agents — Fours Doc — The integration allowlist of connected systems; organization agents limited to organization-level integrations, whose changes need an org admin; knowledge bases attached in Read or Edit mode, never delete; the Tool Approval Required card, offered only in an interactive solo chat in the web workspace, on the main thread, and not in a channel, a Slack or Teams DM or a sub-thread; failover named in the reply, and usage-limit cards; a channel turn stopping when any agent it needs cannot get a model, with none of the channel's other agents answering; Stop and Cancel goal; only your steer amending a goal's objective; the memory recall indicator, Settings → Personal → Memory, correction in place, decaying confidence, and organization-shared memories whose Edit and Delete buttons are disabled
- Insulin Channels — Fours Doc — Planner as the coordinator of an organization channel and the only agent that delegates there, with no integrations and no personal data; specialist agents in a personal channel able to hand off to each other; no tool-approval card on channel turns
- Insulin Jobs — Fours Doc — A job running within its creator's scope and visible only to its owner, organization administrators included; filters in a safe, sandboxed expression language; persisted Steps transcripts; automatic runs limited to 60 an hour per job and 300 an hour per organization, fixed with no setting; a manual job's Run skipping the limit and Run now bypassing the enabled check; one in-flight run per job; Terminate and Enable/Disable
- Insulin Getting Started — Fours Doc — The organization sandbox pool, provisioned the first time an organization-owned agent runs a job, on an org-admin-only tab with Start, Stop, Destroy and Auto-stop; org admins reaching other members' self-owned rows except jobs; only the owner deleting an agent; org-wide shares never granting ADMIN; only org admins creating organization-level resources and connecting organization integrations
- Insulin Marketplace — Fours Doc — Skills added by upload, GitHub import or SkillsMP; provenance badges on skill cards; Enable/Disable; a .zip package importing directly with no review step, its scripts kept for runtime loading; GitHub repo, folder and blob URLs importing the full package directly; Organization-store imports, edits and deletes requiring an org admin
- Insulin Knowledge Bases — Fours Doc — Deprecate and Restore for indexed files, and a sync that never brings a deprecated document back into search
- Integrations MCP (Model Context Protocol) — Fours Doc — The three Access levels on the card for Fours' own MCP server, Read only by default; Access only narrowing the tools on offer; other MCP servers exposing whatever tools they offer
- Integrations Zuora — Fours Doc — An organization-level connection only, which every Fours user in the organization shares
- Integrations Ironclad — Fours Doc — An acting user fixed at connect time for every request and everyone in the organization, and the advice to use a dedicated integration user rather than a real employee's account
- Integrations ServiceNow — Fours Doc — The integration user's roles setting the ceiling on everything the integration can do, and the advice to use a dedicated account, never a real person's
- Insulin Payment, Limits, and Top-Ups — Fours Doc — The monthly spending limit, which pauses AI requests for the rest of the month and applies straight away when set below the month's spend
Keep reading
Stay Updated
New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.
Follow Fours on LinkedIn