Skip to main content
Security teams think in the OWASP lists for AI systems. This page takes each entry of the OWASP Top 10 for LLM Applications 2026 and the OWASP Top 10 for Agentic Applications 2026 and states what Parmana does about it. Parmana sits between an AI agent and the systems it acts on. It decides whether an action may run, releases only approved actions, and signs a record of each one. It does not see or filter what the model reads or writes, so risks about the model itself are outside it. The ratings say so plainly:
  • Covered: Parmana enforces a control for the risk, for every action that goes through it, with evidence you can run.
  • Partly: Parmana limits what the risk can lead to, or covers part of it. The rest is named.
  • Not covered: the risk is about the model, its data or its runtime, which Parmana does not see. Where Parmana still limits the damage, the entry says how.
Evidence refers to sections of docs/CLAIMS.md (for example 2.47), threats in THREAT-MODEL.md (T1 to T18), and attack scenarios you can run with npm run evaluate -- EV-xx (Evaluate Parmana). Open issues are named by their entry in Limitations.

OWASP Top 10 for LLM Applications 2026

OWASP Top 10 for Agentic Applications 2026

Reading this page

  • “Covered” is for actions that go through Parmana. An agent that can also call a system directly is not governed there. Give agents credentials only to Parmana.
  • Each rating has evidence you can check. Run the named attack scenarios with npm run evaluate, or read the claim and its tests in docs/CLAIMS.md.
  • Open issues that touch these risks are G-50 (approvers are not limited to particular actions or policies), G-51 and G-76 (declared facts are not checked against another system; they can only refuse) and G-82 (an external endpoint’s answer is its claim). See Limitations.
  • For regulation (EU AI Act, NIST AI RMF, ISO/IEC 42001, RBI), see Regulation mapping.
  • The lists are OWASP’s. Entry names and order are from the 2026 editions. This page maps Parmana to them; it is not an OWASP assessment or endorsement.