OWASP LLM & agentic AI

Reduce excessive agency, data exposure, and supply-chain risk.

OWASP's GenAI risk lists name prompt injection, sensitive-information disclosure, supply chain, and excessive agency. Use this checklist to apply controls to AI agents.

Why this matters

OWASP's GenAI security work highlights risks like prompt injection, sensitive-information disclosure, supply chain, and excessive agency. These are technical risks AppSec and AI security teams own.

Many of them come down to one thing: what an agent is allowed to do, and what it can reach.

Bakara helps limit excessive agency by controlling tools, skills, prompts, workflows, and permissions.

Mapping

Map OWASP risks to agent controls.

Risk area

Excessive agency

Control with Bakara

Restrict which tools, actions, and permissions an agent can use; block high-impact capabilities.

Risk area

Sensitive information disclosure

Control with Bakara

Label sensitive data and restrict which agents and roles can reach it.

Risk area

Supply chain

Control with Bakara

Keep a register of AI models, MCP servers, and APIs agents can call; review before use.

Risk area

Insecure tool / plugin use

Control with Bakara

Approve tools per role, expire unused ones, and flag tools that appear outside policy.

Hardening checklist

Controls to put in place.

Limit agency

  • Are agent capabilities scoped to what each role needs?
  • Are high-impact actions blocked or approval-gated?
  • Can capabilities be expired or revoked quickly?

Protect data

  • Is sensitive data labeled?
  • Are agents restricted from regulated or secret data unless approved?
  • Are data-access decisions logged?

Govern the supply chain

  • Do we know which external AI tools and models agents call?
  • Are new tools reviewed before use?
  • Are unapproved tools flagged?

Lower agentic AI risk with real controls.

Bakara helps AppSec and AI security teams control what agents can do and reach — and prove it.

Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.