It exists because the classic web list does not cover this ground. The risks it names — prompt injection, insecure handling of model output, supply-chain problems in models and plugins, sensitive data ending up in a response, excessive permissions granted to an agent — do not map onto injection, broken access control and the rest without losing the thing that makes them distinctive.
Used well, it is a conversation starter rather than a certificate. Walking an architecture against the list surfaces the question that matters — what can this system do when the model is wrong — earlier and more cheaply than finding out in production. Used badly, it becomes a checklist to sign off, which is the failure mode of every list of this kind.
Related terms
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
AI agent
A language model given tools it can call and a goal to pursue, so it decides the steps rather than following a fixed script.
Data exfiltration
Getting data out of a system that was not supposed to let it leave.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
