Skip to content

other

Excessive Agency

OWASP vulnerability category covering LLM systems that can take damaging actions because they have more functionality, permissions or autonomy than their task needs.

Known aliases

  • LLM06

Relationships

No evidence-backed relationships are recorded.

Current clusters

build1 publisher

Tool permissions set the maximum harm a hijacked security agent can do

Dev.to author dharani2d argues agent security depends on who picks the next tool call, citing Excessive Agency's rise from sixth to third at OWASP. The proposed control plane keeps identity, authorization, argument checks and approvals in deterministic code outside the model.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40