09 · FRAMEWORKS & STANDARDS

Frameworks & standards the source publications Helmwart interprets

Six core taxonomy and framework publications are explained here. OWASP Threats & Mitigations v1.1 owns T1–T17; Helmwart normalizes the MAS Guide's scenario-scoped extensions into stable internal navigation entries and retains the renumbered RPA source IDs as labels. Supporting NIST, CISA, and other control references are catalogued on the Sources page.

04A OWASP Agentic AI: Threats & Mitigations the master taxonomy

Agentic AI: Threats and Mitigations v1.1 (Dec 2025) owns T1T17. The older MAS Threat Modelling Guide v1.0 (Apr 2025) publishes scenario-specific extended threats and reuses some identifiers across its worked systems. Helmwart presents stable entries as T18–T49 and displays the RPA guide entries originally numbered T16/T17 as T48/T49. This merged numbering is Helmwart's normalization, not an OWASP-issued master catalog.

T1–T49 Master threat catalog 49 threats · v1.1 + MAS Guide v1.0

49 threats grouped by the v1.1 Decision Path. Each step lists base T1–T17 threats and the MAS Guide extensions that build on them. Cards carry MAESTRO layer, agentic factor, ATLAS technique, and mitigation chips.

04B OWASP Top 10 for Agentic Applications 2026 practitioner compass into the master taxonomy

A separate OWASP publication ("ASI Top 10", v2026, December 2025) that surfaces ten agentic risks in the standard OWASP Top 10 format. Its Appendix A links into OWASP threat material; Helmwart additionally shows related normalized MAS scenarios as editorial cross-references. Use it as a fast on-ramp; use the T-catalog when you need detail.

ASI01 Agent Goal Hijack

An attacker manipulates an agent's objective, task selection, or decision pathway (via injected prompts, deceptive tool outputs, forged peer messages, or poisoned retrieval data) so that the agent pursues the attacker's goal rather than the operator's.

Helmwart cross-reference to base and MAS-derived entries: T6T7T18T19T48
OWASP LLM Top 10: LLM01:2025LLM06:2025
ASI10 Rogue Agents

A rogue agent is one whose behavioural objective has drifted from its authorised purpose, yet its identity still checks out, its actions remain inside its permissions, and its logs look clean.

Helmwart cross-reference to base and MAS-derived entries: T13T14T15T38T47
OWASP LLM Top 10: LLM02:2025LLM09:2025

Source: OWASP Top 10 for Agentic Applications 2026 → · Side-by-side explainer: DeepTeam framework summary →

04C OWASP LLM Top 10 for LLM Applications 2025 practitioner compass for the LLM substrate

The OWASP LLM Top 10 (2025) ranks the highest-impact risks for LLM-based applications. It predates agentic systems but stays load-bearing: every agent runs on an LLM, so every LLM Top 10 risk surfaces in the agent loop with a different blast radius. Each card links to the Helmwart "in agentic systems" page, where the OWASP definition is preserved and the agentic delta is added.

Source: OWASP LLM Top 10 for LLM Applications 2025 →

04D MAESTRO: seven layers + cross-layer layered methodology, applied to OWASP threats

MAESTRO (OWASP, v1.0 Apr 2025) decomposes an agentic system into seven architectural layers (L1–L7) plus a Cross-Layer category for emergent multi-agent failures. Each card shows the layer's scope, how many catalog threats touch it, and example T-numbers. Open a card for the full layer prose.

Full MAESTRO reference: seven-layer overview with per-layer prose →

04E MAS Threat Modelling Guide companion catalog · T18–T49

The OWASP MAS Guide v1.0 (Apr 2025) is the older companion publication containing multi-agent scenario threats that Helmwart normalizes as T18–T49. Because the source guide reuses some IDs between worked systems, this site provides stable navigation entries rather than claiming a one-to-one OWASP catalog. The renumbered RPA source entries T16 and T17 are displayed as Helmwart T48 and T49 with their source IDs alongside them.

T18–T49 MAS Threats index 32 threats · grouped by MAESTRO layer

Layer-grouped browse of the MAS Guide threats, each linking to its detail page with the base v1.1 threat it extends. Use this when you want layer-first reading rather than Decision-Path-first.

04F MITRE ATLAS external red-team pivot · not OWASP

ATLAS is MITRE's adversary-techniques knowledge base for AI systems. Helmwart surfaces ATLAS IDs on threat cards where a clean mapping exists, so detection engineers can move from a Helmwart finding to TTP-level indicators. It is not part of the OWASP source material; the MAESTRO guide briefly discusses how the two compose.

ATLAS MITRE adversary techniques for AI / ML external · MITRE Corp

AML.T#### technique IDs across reconnaissance, initial access, model evasion, exfiltration, and impact. Helmwart maps a threat → ATLAS only where the upstream document or our editorial review supports the link; uncertain cases are left empty rather than fabricated.