Robot Explains Gallery

OWASP Agentic Top 10

A kid-friendly visual interpretation of the OWASP Top 10 for Agentic Applications — when AI can plan, act, use tools, and cause real consequences.

Two lists, paired — because neither covers the other's ground:

  • Agentic Top 10: risks when AI can act — with tools, memory across sessions, and real consequences.
  • LLM Top 10: risks when AI is part of an app — what it reads, reveals, generates, or mishandles. See the LLM Top 10 →

LLM risk

Robot reads or writes something risky.

Agentic risk

Robot uses tools, identity, memory, or permissions to do something risky.

Advanced visual cards for older learners & grown-ups

Unlike the rest of the library, these are poster cards rather than full lessons, a friendly visual interpretation of the OWASP Top 10 for Agentic Applications, for awareness and discussion. They're best for older learners and grown-ups, and are not a replacement for the official OWASP guidance.

New here? Start with: What is OWASP? 🎮 Play the Agentic Defender Game LLM vs Agentic →

About this set & license

Robot Explains is an independent educational adaptation and is not official OWASP guidance. It is based on the OWASP Top 10 for Agentic Applications by the OWASP Agentic Security Initiative (ASI).

The OWASP material is licensed under Creative Commons Attribution-ShareAlike 4.0 (CC BY-SA 4.0), and these adapted posters are shared under the same license.

LLM vs Agentic: how they relate → OWASP LLM Top 10