ATLAS
The connected threat map for agentic AI
The Atlas is the research behind every finding on the canvas: each threat wired to its mitigations, the design principles it implicates, and the OWASP Agentic, MAESTRO and MITRE ATLAS sources it comes from. Start with threats and mitigations, use primers and scenarios for context, and trace any finding back to where it came from.
If you're new, start here
- Read the introduction to learn why agentic AI is a new security problem, how attackers and defenders think about it, and how the rest of this handbook fits together.
- Read the primers for 9 short pieces that give you the vocabulary (Principles, Agents, RAG, MCP, A2A, Agentic factors, Lethal Trifecta, Governance, Threat-modeling methodologies). About 50 minutes covers them all.
- Skim the frameworks & standards to understand which publications own which T-numbers and how ASI01–ASI10 map onto the master threat catalog.
- Browse threats by severity using the severity filter to start with the highest-rated threats; each card names the MAESTRO layer and agentic factors that drive the risk.
- Read a case study for worked examples (RPA, ElizaOS, Anthropic MCP) that show how threats cluster in real architectures.
- Try the threat-model workflow, where the four-question wizard uses everything above to generate an audit-ready model for your own system.
New to the terminology? The glossary defines every term used across the Atlas in one place.
Threats 51
All 51 threats grouped by the OWASP v1.1 catalog's six-step Agentic Threat Decision Path. Each step shows base v1.1 threats (T1–T17) plus the multi-agent extensions from the OWASP MAS Guide (T18–T49), plus T50–T51, which are Helmwart's own and not in any OWASP document, in their own section. Every card is tagged with MAESTRO layers, agentic factors, and MITRE ATLAS techniques where a direct counterpart exists. Filter by severity, layer, or factor.
Mitigations what you can actually deploy
68 structured mitigation entries tiered by maturity: Tier 1 production-canonical, Tier 2 real-composable, Tier 3 research-stage. Each entry lists the OWASP threat numbers it covers. On the canvas, a finding's drawer offers Place control for each mitigation that covers it, and residual risk recomputes as you place them. Filter by tier, authoring status, or the threat numbers a control addresses.
Playbooks proactive · reactive · detective
The six mitigation playbooks from OWASP Agentic AI v1.1, one per step of the Agentic Threat Decision Path. Each playbook contains Proactive (prevention), Reactive (response), and Detective (monitoring) actions, mapped onto the Helmwart mitigations that implement them.
Primers vocabulary first
Short orientations covering Agents, RAG, MCP, A2A, Agentic Factors, and the Lethal Trifecta, for readers who need vocabulary before threat content makes sense. Each primer is intentionally narrow. Read these first if you're new.
Case studies three worked threat models
End-to-end threat models from the OWASP MAS Guide: RPA Expense Reimbursement, ElizaOS (Web3 agent OS), and Anthropic MCP. Each study includes per-MAESTRO-layer system mapping, baseline OWASP threat numbers, 34 extended-threat appearances across the three studies (drawn from the 32-entry T18–T49 catalogue), cross-layer scenarios, and a matching canvas template.
HITL program the escalation flow end-to-end
HITL is a pattern, not a threat. This page names the ten-step escalation flow that ties twelve Helmwart mitigations into one program, routed by the consequence of the action and whether it can be undone rather than by model confidence alone: high confidence never authorises a high-impact action by itself.
MAS threats T18–T49 from the MAS Guide
Helmwart's 32-entry normalized extension catalog based on the OWASP MAS Threat Modelling Guide v1.0 (Apr 2025). The guide uses some IDs for different system-specific variants; Helmwart provides stable navigation entries and displays the RPA source entries T16 / T17 as T48 / T49 to avoid collisions with v1.1. Each entry maps onto MAESTRO layers and cross-references a closest v1.1 base threat where useful.
Principles security design principles for agentic AI
The complete set of security design principles as they apply to autonomous agents: Zero Trust, least privilege, least agency, the lethal trifecta, fail-securely, confused-deputy, and more. Each has a plain definition, why it changes for agents, worked scenarios, failure modes, framework mappings, the controls that uphold it, and first steps to apply it.
Frameworks & standards the publications we interpret
Six core taxonomy and framework publications define the threat-model structure here: two OWASP threat-model sources, two OWASP Top 10 awareness lists, the Cloud Security Alliance's MAESTRO framework as applied by the MAS Guide, and MITRE ATLAS as an external adversary-TTP knowledge base. Supporting control sources appear on the Sources page.
Deeper detail pages
Two deeper-detail pages that build on the nine sections above. Each is self-contained but assumes you have at least skimmed the relevant section.
Need a guided walk-through rather than a catalogue? Try the four-question threat-modelling workflow, or read the methodology & tools primer to see how Helmwart sits next to STRIDE-GPT, IriusRisk, ASTRIDE, and the rest of the 2026 landscape.