Securing an LLM agent harness, layer by layer
A structured catalog of the threats that arise when model output is turned into tool calls and actions — each with concrete mitigations, the limits of configuration, and how four common runtimes handle it by default. Mapped to the OWASP Top 10 for Agentic Applications (2026).
How to use this reference
The layered model
Agent security failures rarely stay in one place. A threat enters at one layer and causes damage at another — a poisoned document at the retrieval layer drives a tool call that exfiltrates data at the egress layer. Each layer is treated as an independent control point, on the assumption that the ones above it may be breached.
OWASP Top 10 for Agentic Applications (2026)
Published December 2025, these ten categories describe the risks most likely to compromise autonomous agents. Every threat in the catalog is tagged with the categories it maps to.
Runtime landscape
The four runtimes compared here occupy different points on a single axis: the more capable the built-in agent loop, the more safety controls it ships — and the barer the runtime, the more of the defense the surrounding harness must provide.
Ollama and LM Studio are the same class of tool — local model runners exposing an OpenAI-compatible API with KV caching and function calling — but differ in posture: LM Studio defaults to a localhost-only server and a built-in MCP client with trust prompts, while Ollama is server-oriented, has no built-in MCP, and carries the ecosystem's main real-world exposure risk. See the full comparison.