03 · PLAYBOOKS

Playbooks proactive · reactive · detective

Six playbooks structured from OWASP Agentic AI v1.1: 121 Helmwart action entries across 6 playbooks, mapped onto 66 Helmwart mitigations. Each playbook follows an OWASP Decision Path step and the source's Proactive, Reactive, and Detective organization; Helmwart adds implementation-specific actions and mappings.

P1Step 1: Does the AI agent independently determine the steps needed to achieve its goals?

Preventing AI Agent Reasoning Manipulation

Stop attackers from rewriting an agent’s plan or hiding its tracks.

Goal: Prevent attackers from manipulating AI intent, security bypasses through deceptive AI behaviours, and enhance AI actions traceability.

P5Step 5: Does AI require human engagement to achieve its goals or function effectively?

Protecting HITL & Preventing Decision Fatigue Exploits

Keep human oversight effective when the agent fan-out tries to swamp it.

Goal: Prevent attackers from overloading human decision-makers, manipulating AI intent, or bypassing security through deceptive AI behaviours.

Source basis: OWASP Agentic AI: Threats and Mitigations v1.1 (Dec 2025), §Mitigation Strategies. OWASP supplies the six playbooks, threat coverage, and step structure. Helmwart expands them with implementation-oriented actions and per-action mappings onto deployable controls.

Source and licence

Parts of this page are adapted from OWASP Agentic AI — Threats and Mitigations v1.1, December 2025. Because that work is licensed CC BY-SA 4.0, this page is distributed under CC BY-SA 4.0 as well. CC BY-SA 4.0