-
-
Notifications
You must be signed in to change notification settings - Fork 280
Update ASI07 Insecure Inter-Agent Communication #729
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Update ASI07 Insecure Inter-Agent Communication #729
Conversation
itskerenkatz
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
AMAZING WORK
I have left a few minor comments, the most important of them is the lack of mapping to former OWASP frameworks (see in the comment)
...tic-top-10/Sprint 1-first-public-draft-expanded/ASI07_Insecure_Inter_Agent_Communication .md
Outdated
Show resolved
Hide resolved
...tic-top-10/Sprint 1-first-public-draft-expanded/ASI07_Insecure_Inter_Agent_Communication .md
Outdated
Show resolved
Hide resolved
...tic-top-10/Sprint 1-first-public-draft-expanded/ASI07_Insecure_Inter_Agent_Communication .md
Outdated
Show resolved
Hide resolved
- Add Reference Links section mapping ASI07 to OWASP Top 10 for LLMs (LLM01, LLM03-06), Agentic AI Threats, and AIVSS - Add Example 7 on Agent Identity Impersonation and Spoofing Attacks - Add Scenario G demonstrating identity spoofing in healthcare multi-agent system - Add mention of data exposure between agents with different permission levels - Update reference titles for accuracy (Byzantine Fault Tolerance, Resilient Consensus) - Reorganize references into single numbered list following ASI document format Addresses feedback from @itskerenkatz in PR OWASP#729
|
Thanks a lot for your review @itskerenkatz, I've addressed your feedback! |
41e0be3 to
940e0d7
Compare
- Add Reference Links section mapping ASI07 to OWASP Top 10 for LLMs (LLM01, LLM03-06), Agentic AI Threats, and AIVSS - Add Example 7 on Agent Identity Impersonation and Spoofing Attacks - Add Scenario G demonstrating identity spoofing in healthcare multi-agent system - Add mention of data exposure between agents with different permission levels - Update reference titles for accuracy (Byzantine Fault Tolerance, Resilient Consensus) - Reorganize references into single numbered list following ASI document format Addresses feedback from @itskerenkatz in PR OWASP#729
Aligns ASI07 with the official OWASP Top 10 for Agentic Applications 2026 [1]. Replaces the placeholder template with finalized content. Covers T12 (Agent Communication Poisoning) and T16 (Insecure Inter-Agent Protocol Abuse) from Agentic Threats and Mitigations. Adds attack scenarios for MCP descriptor poisoning and A2A registration spoofing. [1]: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
940e0d7 to
fcb26ba
Compare
|
@itskerenkatz I've updated this PR with the final content of the entry as discussed. |
Expanded the ASI07 Insecure Inter-Agent Communication document with comprehensive vulnerability analysis and mitigation strategies.
Changes