HackMyIP
← Back to News
2026-08-21 Dark Reading

OWASP Unveils Top 10 AI Security Risks with Universal Skill Format

AI SecurityAI ThreatsSupply Chain

The Open Worldwide Application Security Project (OWASP) has published its latest Top 10 security risk list, this time tailored specifically for the rapidly evolving AI landscape. The new blueprint addresses vulnerabilities unique to AI-powered applications, including risks associated with agentic AI systems, model context protocols (MCP), and AI add-ons known as "skills." OWASP's goal is to help developers and security teams identify and mitigate threats that traditional security frameworks often overlook in AI-integrated environments.

A standout feature of the new list is the introduction of the Universal Skill Format (USF), a standardized specification designed to bring consistency and security to AI skill deployment. The USF provides a structured way to define, package, and validate AI capabilities, reducing the risk of supply chain attacks and malicious code injection through third-party AI components. By standardizing how AI skills are described and distributed, OWASP aims to prevent the fragmentation that has historically plagued plugin and extension ecosystems. Organizations deploying AI agents should audit their skill inventories and verify that each component originates from a trusted source — a practice that aligns with broader privacy checkup protocols for any software supply chain.

Several of the flagged risks overlap with familiar security concerns but carry new dimensions in AI contexts. Prompt injection remains a top concern, now compounded by the expanded attack surface created by MCP-connected tools and autonomous agents capable of executing actions on behalf of users. Other highlighted risks include data poisoning during model training, sensitive information disclosure through model outputs, and excessive agency granted to AI systems without proper guardrails. Security teams should also reassess authentication mechanisms protecting AI endpoints, since compromised credentials can cascade into broader system access. A reliable password checker can help ensure that accounts managing AI infrastructure are not relying on weak or previously breached credentials.

OWASP's blueprint arrives as enterprises accelerate adoption of generative AI and agentic workflows, often without dedicated security oversight. The organization recommends that security teams integrate AI-specific risk assessments into existing vulnerability management programs, including routine network exposure scans to identify exposed AI services and endpoints. By aligning AI deployments with the new Top 10 framework, organizations can establish a baseline for secure AI integration while preparing for forthcoming regulatory requirements around AI governance and transparency.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →