OWASP ASI01: Mapping Every Agent Goal Hijack Variant to Detection and Defense
Blog post from Galileo
In December 2025, the OWASP Foundation introduced the Top 10 for Agentic Applications, a framework highlighting ten security risk categories for AI agents, with ASI01, Agent Goal Hijack, being the top-ranked category. This vulnerability involves attackers redirecting an AI agent's objectives using crafted prompts or corrupted data, leading to a series of autonomous actions that pursue the attacker's goals. Such attacks exploit the agent's inability to distinguish genuine instructions from malicious ones, creating a broad attack surface that includes anything the agent reads. This has prompted enterprises to develop separate governance controls for agent-level and LLM-level systems. The text details various attack patterns and emphasizes the importance of detecting injections on all agent inputs, not just user ones, while also advocating for limiting the damage of undetected injections through strict permission controls and monitoring. The document advocates for a comprehensive approach combining detection and architectural controls to mitigate these risks, stating that while some guardrails catch direct prompt injections, they often miss more subtle variants, necessitating continuous updates and domain-specific evaluations.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| LLM | 5 | 5,932 | 1,046 | 223 | -2% |
| RAG | 4 | 941 | 216 | 85 | -48% |
| AI Agents | 3 | 4,430 | 1,100 | 236 | -3% |
| AI Coding Assistant | 3 | 1,480 | 382 | 153 | +18% |
| Multi-agent systems | 3 | 460 | 170 | 68 | -20% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.