OWASP 'State of Agentic AI Security' v2.01: coding agents dominate, prompt injection still the root failure
Help Net Security·high signal
OWASP's 2026 report (covered June 11) finds 28 of 53 tracked agentic projects are coding agents, with the five fastest-growing tools (Claude Code, Gemini CLI, Codex, Cline, Aider) all in that category. Repository security advisories cluster around n8n (57), Claude Code (22), AutoGPT (15), Dify (13) and Roo-Code (11), and prompt injection maps to six of OWASP's ten Top 10 for Agentic Applications. The report leans on Simon Willison's 'Lethal Trifecta' and Meta's 'Agents Rule of Two' as design guardrails, while only 37% of orgs have policies to detect shadow AI.