Why This List
From Threats to Governance
Organized along the "Attack Surface β Hardening β Evaluation β Governance" pipeline, covering three authoritative source families.
Attack Surface
Know your enemy β understand the threats facing agentic AI systems
Hardening Techniques
Proactive defense β reduce the attack surface of your systems
Evaluation & Testing
Measure and validate β ensure defenses actually work
Governance & Standards
Institutional guardrails β policies, standards, and compliance
| Source | Coverage |
|---|---|
| OWASP Agentic Top 10 (2026) | All ASI01βASI10 risk items |
| arXiv Academic Surveys | 5 threat categories + 4 defense categories |
| NIST / McKinsey / CSA | Full governance coverage |
Taxonomy
12 Categories, 4 Groups
A comprehensive taxonomy covering the full lifecycle of agentic AI security.
Threat Landscape
Prompt Injection & Jailbreaks
Direct/indirect injection, multimodal injection, multilingual obfuscation, payload splitting
Tool Misuse & Autonomous Exploitation
Unauthorized tool invocation, CVE exploitation, SQL injection chains, code execution escapes
Memory & Context Poisoning
Long-term memory poisoning, RAG data contamination, session context tampering
Multi-Agent & Protocol-Level Threats
MCP/A2A protocol attacks, rogue agent registration, cross-agent transitive injection
Identity, Privilege & Supply Chain
Non-human identity management, privilege abuse, credential theft, supply chain poisoning
Hardening Techniques
Prompt Hardening & Input Sanitization
Instruction isolation, sandwich defense, delimiter strategies, paraphrase detection
Runtime Sandboxing & Capability Confinement
Runtime sandboxing, least-privilege tool invocation, capability-based access control
Detection, Monitoring & Observability
Behavioral anomaly detection, tool call chain auditing, real-time intent monitoring
Multi-Agent Security & Protocol Hardening
MCP/A2A authentication, agent identity verification, cross-agent trust chain management
Evaluation & Testing
Mapping
Threat β Defense
Each threat category maps to specific hardening techniques. Here's how they connect.
Get Involved
Help Build the List
Agentic Hardening is community-driven. Every contribution helps the entire ecosystem.
Star & Share
Star the repo on GitHub to help others discover it, and share with your network.
Star on GitHubSubmit Resources
Found a paper, tool, or framework? Open a PR following our contribution guidelines.
Contributing GuideReport Issues
Spot a broken link, outdated entry, or missing category? Let us know via GitHub Issues.
Open an Issue