> ## Documentation Index
> Fetch the complete documentation index at: https://docs.parmanasystems.com/llms.txt
> Use this file to discover all available pages before exploring further.

# OWASP mapping

> Each risk in the OWASP Top 10 for LLM Applications (2026) and the OWASP Top 10 for Agentic Applications (2026): what Parmana does about it, the evidence, and what it leaves to you.

Security teams think in the OWASP lists for AI systems. This page takes each entry of the
[OWASP Top 10 for LLM Applications 2026](https://genai.owasp.org/initiatives/top-10-for-llm-and-genai/) and the
[OWASP Top 10 for Agentic Applications 2026](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
and states what Parmana does about it.

Parmana sits between an AI agent and the systems it acts on. It decides whether an action may run, releases only
approved actions, and signs a record of each one. It does not see or filter what the model reads or writes, so
risks about the model itself are outside it. The ratings say so plainly:

* **Covered:** Parmana enforces a control for the risk, for every action that goes through it, with evidence you can
  run.
* **Partly:** Parmana limits what the risk can lead to, or covers part of it. The rest is named.
* **Not covered:** the risk is about the model, its data or its runtime, which Parmana does not see. Where Parmana
  still limits the damage, the entry says how.

Evidence refers to sections of [docs/CLAIMS.md](https://github.com/pavancharak/parmana/blob/main/docs/CLAIMS.md)
(for example 2.47), threats in
[THREAT-MODEL.md](https://github.com/pavancharak/parmana/blob/main/THREAT-MODEL.md) (T1 to T18), and attack scenarios
you can run with `npm run evaluate -- EV-xx` ([Evaluate Parmana](/evaluation/overview)). Open issues are named by
their entry in [Limitations](/security/limitations#open-issues).

## OWASP Top 10 for LLM Applications 2026

| Risk | Rating | What Parmana does | Evidence | What remains |
| - | - | - | - | - |
| LLM01 Prompt Injection | Partly | Does not detect injection. Limits what an injected agent can do: no action runs without a person's signed approval for that action and resource, facts the agent declares cannot authorize, and its key is limited to named actions. | 2.44, 2.47; T1, T2, T4; EV-04, EV-06, EV-12 | Parameters an approval does not fix (for example a message's text) are the agent's choice. A person can be persuaded to approve. |
| LLM02 Sensitive Information Disclosure | Partly | Connector credentials are resolved inside the gateway at release and never reach the agent, a decision or a record. | 2.23; T10; EV-10 | What the model reads, and what it says, is outside Parmana. |
| LLM03 Excessive Agency | Covered | The core purpose. Each API key may call named actions only. Each action is bound to one policy. Every action needs a signed human approval for that action, resource and amount. Approval and authorization are single use and expire. Only the gateway can release an action. | 2.8, 2.16, 2.22, 2.47, 3.1, 3.16; T1, T2, T5, T6, T9; EV-01 to EV-05, EV-11, EV-12 | Actions the agent can take by other routes are outside Parmana. Any trusted approver can approve any action (G-50). |
| LLM04 Supply Chain | Partly | Parmana's own supply chain: actions and base images pinned to exact digests, CodeQL and dependency review on every change, signed build provenance and an SBOM with every SDK release. Connectors are registered through maker checker. | 2.49; T17 | Models, model files and datasets are outside Parmana. |
| LLM05 Data and Model Poisoning | Not covered | Parmana has no model or training data. A poisoned model is limited the same way as an injected one: it still cannot act without a signed approval. | 2.47 | Detecting poisoning is outside Parmana. |
| LLM06 Unbounded Consumption | Partly | Per caller rate limits on `/execute` and on failed authentication; request bodies have a size limit. | 3.14; T16 | Model tokens and cost are outside Parmana. |
| LLM07 Misinformation | Not covered | Parmana does not judge whether the model is right. A wrong conclusion still cannot become an action without a person's signed approval, and the signed record shows exactly what was approved and done. | 2.5, 2.47 | Checking facts is outside Parmana. |
| LLM08 Hidden Context Exposure | Not covered | Parmana keeps two things out of the agent's context: connector credentials, and policy rule conditions (the server tells an agent what a request must carry, never the rules). | 2.23, 2.48 | The agent's own prompt and context are outside Parmana. |
| LLM09 Vector and Embedding Weaknesses | Not covered | Parmana uses no retrieval or embeddings. | None | Outside Parmana. |
| LLM10 Improper Output Handling | Partly | Model output that would become an action is checked before it runs: each connector forwards only listed parameters, signals must equal the action's own values and have the declared types, targets are validated (for example a GitHub repository), and an external endpoint must be public and receives only allowed parameters. | 2.44, 2.50, 2.52; T4, T18; EV-06 | Other uses of model output (shown to users, stored, run as code) are outside Parmana. |

## OWASP Top 10 for Agentic Applications 2026

| Risk | Rating | What Parmana does | Evidence | What remains |
| - | - | - | - | - |
| ASI01 Agent Goal Hijack | Partly | A hijacked agent can ask, but cannot act: every action needs a signed human approval for that action and resource, and declared facts cannot authorize. | 2.44, 2.47; T2, T4; EV-04, EV-06 | Within an approved action and resource, unfixed parameters are the agent's choice. Detecting the hijack is outside Parmana. |
| ASI02 Tool Misuse and Exploitation | Covered | Tools are reached only through the gateway, after a policy per action and a signed approval. Each connector forwards only listed parameters; Slack posts only to listed channels; external endpoints must be public and are pinned to the addresses checked. | 2.47, 2.50, 3.1; T2, T9; EV-04, EV-11 | Tools the agent can reach without Parmana are outside it. An external endpoint's answer is its claim (G-82). |
| ASI03 Identity and Privilege Abuse | Partly | Each API key is limited to named actions, principals and tenants, and the server, not the agent, records who submitted a request. Connector credentials stay inside the gateway. Approver keys are added and revoked through maker checker. | 2.16, 2.23, 2.45, 3.16; T1, T10, T11; EV-10, EV-12 | Any trusted approver can approve any action or policy change (G-50). |
| ASI04 Agentic Supply Chain Vulnerabilities | Partly | Connectors to external systems are registered through maker checker, each bound to one policy, and every release to them is signed. Parmana's own build is pinned, scanned and released with provenance and an SBOM. | 2.49, 2.50; T11, T17 | MCP servers, plugins and tools the agent loads itself are outside Parmana. |
| ASI05 Unexpected Code Execution | Not covered | Parmana runs no code from agents or policies: a policy is data, and a `matches` pattern with a nested quantifier is refused. | 2.3 | Code the agent runs in its own environment is outside Parmana. |
| ASI06 Memory and Context Poisoning | Not covered | A poisoned memory can lead an agent to ask for the wrong thing, which still needs a signed approval. Facts are checked again at release, so a change between approval and execution is refused. | 2.29, 2.47; T7; EV-09 | The agent's memory is outside Parmana. |
| ASI07 Insecure Inter-Agent Communication | Not covered | Each agent is a separate caller with its own key and limits; one agent cannot act with another's. Releases from Parmana to external endpoints are signed and verifiable. | 2.16, 2.50, 3.16 | Messages between agents are outside Parmana. |
| ASI08 Cascading Failures | Partly | Fails closed: a misconfigured server refuses to start, an audit write failure refuses the request, an action whose outcome is unknown is reported as such (`502`), and a business transaction id runs once. | 2.17, 2.19, 2.20; T8, T15; EV-15 | Failures inside other agents and systems are outside Parmana. |
| ASI09 Human-Agent Trust Exploitation | Partly | An approver signs a specific action, resource and amount, not a general permission; each approval is single use and expires. The `approval.needed` event names exactly what to sign. | 2.42, 2.46, 2.47; T3; EV-05 | A person can still be persuaded to approve a request they did not read closely. |
| ASI10 Rogue Agents | Partly | A rogue agent holds only its API key: limited to named actions, unable to approve, and every action it takes is signed and recorded. Its key can be revoked. | 2.5, 2.16, 2.47, 3.16; T1, T2, T12 | Detecting that an agent has gone rogue is outside Parmana. |

## Reading this page

* **"Covered" is for actions that go through Parmana.** An agent that can also call a system directly is not
  governed there. Give agents credentials only to Parmana.
* **Each rating has evidence you can check.** Run the named attack scenarios with `npm run evaluate`, or read the
  claim and its tests in `docs/CLAIMS.md`.
* **Open issues that touch these risks** are G-50 (approvers are not limited to particular actions or policies),
  G-51 and G-76 (declared facts are not checked against another system; they can only refuse) and G-82 (an external
  endpoint's answer is its claim). See [Limitations](/security/limitations#open-issues).
* **For regulation** (EU AI Act, NIST AI RMF, ISO/IEC 42001, RBI), see [Regulation mapping](/security/regulation-mapping).
* **The lists are OWASP's.** Entry names and order are from the 2026 editions. This page maps Parmana to them; it is
  not an OWASP assessment or endorsement.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.