Key categories: prompt injection; sensitive information disclosure; supply-chain risks (models, datasets, plugins and MCP servers); data and model poisoning; improper output handling (rendering model output as HTML or running it as SQL or shell); excessive agency (too many tools or permissions); system prompt leakage; vector and embedding weaknesses (cross-tenant leakage in a shared vector store); misinformation; and unbounded consumption (cost and denial-of-service through huge or looping requests).
Walk your flagships through the list and write down one mitigation per relevant item. That document is a strong portfolio artefact.
Note the overlap with classic web security: output handling is XSS and injection again, and excessive agency is least privilege again.
Going deeper
OWASP also published a Top 10 for agentic applications (December 2025), covering risks like tool misuse, privilege compromise, memory poisoning and cascading failures across agents. Read it alongside the LLM list for Flagship 2.