Skip to content

This repository contains examples of insecure code and/or security misconfigurations in common Agent frameworks

License

Notifications You must be signed in to change notification settings

GenAI-Security-Project/GenAI-Agent-Security-Initiative

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 

Repository files navigation

image

OWASP Agentic Security Initiative (ASI) - Insecure Agent Samples

Warning

The sample applications here are deliberately insecure to demonstrate Agent security risks. Please exercise caution when deploying in your environment.

Objective

We aim to demonstrate security risks in well-known Agentic AI (also known as Agents) frameworks, particularly how Agent misconfigurations (i.e., insecure code, framework-specific misconfigurations) can lead to vulnerabilities identified in the OWASP Top 10 for Gen AI and Large Language Model Applications 2025.

This repository contains examples of insecure code and/or security misconfigurations in common Agent frameworks such as:

  1. LangChain
  2. LangGraph
  3. CrewAI
  4. AutoGen
  5. OpenAI Swarm (Experimental)
  6. Amazon Bedrock Agents

More Agent frameworks will be supported in the future.

Structure

The framework folder contains subdirectories for each framework with individual examples of vulnerable agents. Each example is accompanied by a description of the vulnerability.

Contributing

The guidelines for contributing are described in the CONTRIBUTING.md file.

How to join the ASI

Visit the ASI project landing page: (https://genai.owasp.org/initiatives/#agenticinitiative)

About

This repository contains examples of insecure code and/or security misconfigurations in common Agent frameworks

Resources

License

Stars

Watchers

Forks