OWASP AIVSS

AIUC-1 × OWASP AIVSS

The OWASP AI Vulnerability Scoring System enables organizations to quantify how agentic capabilities amplify security risks, producing numerical scores (0-10) that combine technical vulnerability severity with agent-specific factors like autonomy, tool access, and memory persistence.

AIUC-1 integrates the OWASP AIVSS, which is a technical contributor to AIUC-1. Certification against AIUC-1:

Covers all agent risks identified in AIVSS

Enables organizations to mitigate risks quantified in OWASP AIVSS

Incorporates AIVSS agent risk amplification factors in standard requirements

OWASP AIVSS crosswalks by risk

AIVSS Risk

Agent Access Control Violation

AIVSS Description

Permission escalation, credential mismanagement, or role inheritance exploitation

AIVSS Risk

Agent Cascading Failures

AIVSS Description

Cross-system exploitation where one compromised agent propagates damage

AIVSS Risk

Agent Goal and Instruction Manipulation

AIVSS Description

Prompt injection and semantic hijacking of agent objectives

AIVSS Risk

Agent Identity Impersonation

AIVSS Description

Spoofing of agent or human identities through deepfakes or credential theft

AIVSS Risk

Agent Memory and Context Manipulation

AIVSS Description

Poisoning persistent memory or exploiting context drift

Relevant AIUC-1 Requirements
AIVSS Risk

Agent Orchestration and Multi-Agent Exploitation

AIVSS Description

Attacks targeting coordination mechanisms between agents

AIVSS Risk

Agent Supply Chain and Dependency Risk

AIVSS Description

Compromised models, libraries, or third-party tools

AIVSS Risk

Agent Untraceability

AIVSS Description

Inability to audit agent decision chains or attribute actions

AIVSS Risk

Agentic AI Tool Misuse

AIVSS Description

Compromised tool selection, insecure invocation, or lack of oversight

AIVSS Risk

Insecure Agent Critical Systems Interaction

AIVSS Description

Unauthorized manipulation of infrastructure, IoT, or operational technology

Last updated February 26, 2026.