OWASP Top 10 coverage: what Preloop does and does not do¶
Editions: OSS, Cloud, Enterprise. Unless stated otherwise, everything on this page ships in OSS.
This page maps Preloop to the OWASP Top 10 for Agentic Applications (2026) and the OWASP Top 10 for LLM Applications (2026), entry by entry. It exists so that anyone grading Preloop's claims (a buyer, an auditor, or a directory such as Yuntona) can quote one stable paragraph per risk and check it against the code.
Rules this page follows:
- Every risk is cited with its taxonomy version.
ASI02:2026is notASI02. - Each entry states the mechanism, the default posture (what happens with no configuration), the edition the control ships in, and the code path in github.com/preloop/preloop.
- Where Preloop does not address the observable property the OWASP entry describes, the entry says Not covered. A control that limits the consequences of a risk is labelled as such and is not presented as detection or prevention.
- Where Preloop's own behaviour is the exposure the entry describes, the entry says so under Polarity.
- Preloop is not a certification, a conformity assessment, or legal advice.
Edition labels used below: OSS is the Apache-2.0 repository. Cloud and Enterprise add users, teams, RBAC, multi-approver workflows and AI-driven approvals. Unless stated otherwise, a control below ships in OSS.
OWASP Top 10 for Agentic Applications, 2026¶
ASI01:2026 Agent Goal Hijack¶
Not covered at the level the entry describes. Preloop does not maintain goal-state or tool-use-pattern baselines and does not detect that an agent's objective has been redirected.
Consequence-limiting controls. Every MCP tool call passes the safety
layer: ordered access rules with CEL conditions on tool
arguments decide allow, deny, or require_approval before execution. A hijacked
agent can only do what its policy permits. Model I/O rules on model.request can
enable a prompt-injection detector toggle. Dedicated semantic prompt-injection
detection is on the roadmap and is not shipped.
Default posture: with no access rules, tool calls are allowed. Code:
backend/preloop/services/policy_evaluator.py, backend/preloop/services/model_content_policy.py.
ASI02:2026 Tool Misuse and Exploitation¶
Mechanism. Preloop sits between the agent and every MCP tool. Access rules are
ordered, carry a priority, and evaluate CEL expressions over the tool's arguments,
not only its name (for example args.amount > 2000 → deny, args.amount > 100 →
require approval). The first matching rule wins. Denied calls return an MCP error the
agent can act on. Tools can additionally require a justification argument; when set
to required, calls without one are rejected. Applies equally to built-in, MCP-proxied
and HTTP tools.
Default posture: no rules → allow. Edition: OSS. Code:
backend/preloop/services/policy_evaluator.py, backend/preloop/services/approval_helper.py.
Docs: Safety Layer, Conditional Approval (CEL),
Per-Tool Justification.
ASI03:2026 Identity and Privilege Abuse¶
Mechanism. Provider API keys and MCP server credentials are held in Preloop's
secret store, encrypted with an application key derived from SECRET_KEY; agents
never receive them. Onboarding mints a per-runtime credential, and the gateway issues
short-lived gateway tokens to enrolled runtimes. Tool lists, allowed-model lists and
budgets resolve per subject (API key or managed agent), so one runtime token sees
only the tools and models intended for it. A subscription credential stored on one
model cannot be used by another agent. Standard MCP clients authenticate with OAuth
2.1 and PKCE.
Default posture: account-level catalogue applies until a subject is scoped. Edition:
OSS; RBAC for humans is Cloud/Enterprise. Code:
backend/preloop/services/subject_governance.py, backend/preloop/services/model_gateway_auth.py,
backend/preloop/services/secret_service.py. Docs: Subject-Scoped Governance,
AI Model Gateway.
ASI04:2026 Agentic Supply Chain Vulnerabilities¶
Partially covered, different scope than most readers expect. Preloop's SBOM Verify, SBOM Exploit Check and Release Security Audit presets check the SBOM of the product your build produced against OSV.dev and CISA KEV. They do not audit the agent's own tool, plugin or MCP server chain.
What does apply to the agent's chain: an agent routed through Preloop can only reach MCP servers registered in the account's tool catalogue, so the catalogue functions as an allowlist of reachable tools. Preloop's own release assets carry Sigstore build provenance and checksums.
Default posture: catalogue allowlist applies to any onboarded agent. Edition: OSS.
Docs: External MCP Tools, security audit presets in the
repository, docs/release-verification.md.
ASI05:2026 Unexpected Code Execution¶
Mechanism. Shell and file tools are governed like any other tool: CEL conditions on
args.command (for example args.command.contains('deploy') && args.command.contains('production'))
can deny or hold a call for approval before it runs. For Claude Code, Preloop's plugin
puts native Bash and Edit calls behind the same approvals. Flow executions run in a
container Preloop launches, or on a private runner you operate.
Default posture: no rules → allow. Edition: OSS. Code:
backend/preloop/services/policy_evaluator.py. Docs: Policy-as-Code,
Claude Code.
ASI06:2026 Memory and Context Poisoning¶
Not covered. Preloop does not attribute memory writes to their source, track write
frequency, or inspect agent memory stores. model.request rules can inspect the prompt
sent to the provider, which is not the same property.
ASI07:2026 Insecure Inter-Agent Communication¶
Partially covered. A flow can start a child flow of the same account. Children run as the same account principal, resolve the same approval workflows, and any approval they raise reaches the same humans, bounded by the account's approval deadline cap. Operator notes delivered to a running agent are recorded with the identity of the sender. Preloop does not authenticate, sign or inspect agent-to-agent messages that do not pass through its gateway or MCP endpoint. Parent/child identity for harness subagents is documented as observed behaviour only; nothing is enforced.
Edition: OSS. Docs: flow delegation and operator notes pages in the repository.
ASI08:2026 Cascading Failures¶
Mechanism (limit and recover). The account kill switch halts an account by scope:
gateway rejects new model requests with HTTP 403 preloop_account_halted; tools
denies MCP dispatch including already-approved calls awaiting replay, and freezes
pending approval deadlines for exactly the time spent halted; flows blocks new
launches and durably requests termination of admitted executions. Hard budgets at
account, flow and subject level deny model calls before they reach the provider.
Child flow executions carry lineage columns, and the execution page renders the
delegation tree, so fan-out from one parent is visible.
Default posture: budgets and kill switch are off until configured/activated. Edition:
OSS. Code: backend/preloop/services/kill_switch.py,
backend/preloop/services/model_gateway_budget_enforcer.py,
backend/preloop/services/flow_delegation_budget.py. Docs: account kill switch page
in the repository, Cost Analytics & Budgets.
ASI09:2026 Human-Agent Trust Exploitation¶
Mechanism. When a call is held for approval, the approver sees the tool name, the
arguments with sensitive fields redacted, the agent's justification if configured,
and the rule that gated the call. Approvals are delivered on mobile, watch, Slack,
Mattermost, email or webhook, and are recorded with approver identity and decision.
Polarity. AI-driven approval workflows (Enterprise) let a model decide approvals
against operator criteria. Decisions below the workflow's confidence threshold follow
its fallback (escalate to a human, deny, or approve). With a permissive threshold
or an approve fallback, an AI approver is itself a trust surface an agent could
exploit.
Edition: human approvals OSS; multi-approver, quorum and AI-driven approvals
Cloud/Enterprise. Code: backend/preloop/services/approval_service.py,
backend/preloop/services/ai_approval_service.py. Docs: Multi-Channel Notifications,
AI-Driven Approvals.
ASI10:2026 Rogue Agents¶
Mechanism (contain and audit). See ASI08 for the kill switch and budgets. Every tool call and model call is attributed to a subject and recorded in one session timeline with the matched rule, decision, approver and spend. Allowed-model lists per subject prevent an agent from switching to a model it was not granted. Session search is audited.
Default posture: attribution and timeline are always on for governed traffic; kill
switch and budgets require configuration. Edition: OSS. Code:
backend/preloop/services/kill_switch.py, backend/preloop/services/session_manager.py,
backend/preloop/services/session_search_audit.py. Docs: Runtime Sessions.
OWASP Top 10 for LLM Applications, 2026¶
Prompt Injection¶
Same position as ASI01:2026. Preloop limits what an injected instruction can do through tool policy, approvals and redaction; it does not detect injection semantically. Content-safety firewalls such as Lakera or Llama Guard can run in front of the gateway.
Sensitive Information Disclosure¶
Polarity: Preloop is part of the disclosure surface described by this entry, and this section describes what it does about it.
Mechanism. The model gateway records a normalized event per model call. When
MODEL_GATEWAY_CAPTURE_CONTENT is true (the default), the event includes a
truncated content preview (bounded by MODEL_GATEWAY_MAX_PREVIEW_CHARS) after
regex redaction of private keys, bearer tokens, api_key/token/secret/password
assignments, and common provider key formats. Set MODEL_GATEWAY_CAPTURE_CONTENT=false
to store no content. Approval notifications and tool execution records pass through
field-name redaction (password, token, api_key, authorization, credential,
private_key, client_secret, webhook_secret and similar). Free-text personal data
inside prompts is not redacted by default.
Default posture: content captured and redacted. With the default limits (32768
characters per message preview, 8192 characters per stored body string) most
conversations are stored in full after redaction. Edition: OSS. Code:
backend/preloop/services/model_gateway_events.py, backend/preloop/utils/redaction.py,
backend/preloop/config.py (model_gateway_capture_content). Docs:
Security & Privacy, Redaction, AI Model Gateway.
Supply Chain¶
See ASI04:2026. Product-SBOM presets; catalogue allowlist for reachable MCP servers; signed provenance on Preloop's own releases.
Improper Output Handling¶
Mechanism. Model I/O rules evaluate model.response after the provider returns
and before bytes reach the client, with the same allow/deny/require_approval
actions as tools. Default posture: no rules → allow. Edition: OSS. Code:
backend/preloop/services/model_content_policy.py.
Excessive Agency¶
Mechanism. The MCP firewall (ASI02:2026), subject-scoped tool and model lists (ASI03:2026) and human approvals (ASI09:2026) together bound what an agent may do. Default posture: no rules → allow.
Unbounded Consumption¶
Mechanism. Gateway budgets at account, flow and subject level have soft and hard
limits; hard limits deny the call before it reaches the provider. Allowed-model lists
per subject stop an agent from moving to a more expensive model. Usage the gateway
cannot price is labelled unpriced, not $0.00. Default posture: no budget until
configured. Edition: OSS; per-user and per-team budgets Cloud/Enterprise. Code:
backend/preloop/services/model_gateway_budget_enforcer.py. Docs:
Cost Analytics & Budgets.
Not covered¶
System Prompt Leakage, Misinformation, Data and Model Poisoning, Vector and Embedding Weaknesses. Preloop has no control aimed at these entries.
Changes to this page¶
Entries change when behaviour changes, with the release that changed it. Corrections: open an issue on github.com/preloop/preloop.