Excessive Agency (LLM06)
An LLM-based agent has more permissions, more tool access, or more autonomy than its task requires. Compromise via prompt injection then uses that excessive privilege to do damage.
- Rank
- LLM06 of 10
- In the check
- Cited by 2 of the 16 questions
What it looks like in practice
Three shapes this risk takes in real deployments.
Example 1
A customer-service agent with write-access to the customer database when read-only would suffice.
Example 2
An agent that can send emails on behalf of the user with no confirmation step.
Example 3
An agent with broad API access that gets injected into making unauthorized calls.
Controls that close it
These count toward the Governance dimension of the check.
Principle of least privilege for agent tools and permissions
Human-in-the-loop confirmation for high-impact actions
Action logging and audit
Scope-limited tokens for tool access
Where the check cites it
The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint.
| Question the check may ask | Dimension | Citation |
|---|---|---|
| Do you know which AI coding agents and assistants are running on staff machines, and what they can reach? | Governance | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
| Do you know which AI coding agents and assistants run on staff machines, what they can reach, and how MCP servers and Skills are vetted before install? | Governance | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
Other frameworks the check cites
Score yourself against this framework.
Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.
- A few minutes for most people
- Free, from CWS
- Your stage, the chart and the next move, by email or live with an engineer