Adversa AIGet a demo

OWASP ASI05 — Unexpected Code Execution: Defense Architecture Technical Reference

  • Whitepaper
  • Agentic AI Security

Adversa AI · March 9, 2026

The full technical reference behind our ASI05 guide — five attack vectors in depth, a five-layer defense architecture, and an architect's checklist.

What's inside

  • Comprehensive deep dives into all five attack vectors — Direct Execution, Deserialization, Template Injection, Configuration Manipulation, and Deferred Execution
  • A complete defense-in-depth architecture framework with five layers of controls and mitigations
  • Detailed checklist for security architects and risk managers

Our definitive guide to OWASP ASI05 provides the high-level taxonomy and technical definitions of unexpected code execution in agentic AI. Building a secure agentic architecture, however, requires detailed mitigation strategies — that is what this whitepaper delivers.

When an AI agent has the autonomy to write and run code, the barrier between a natural-language prompt and remote code execution evaporates. This reference takes each of the five ASI05 attack vectors from taxonomy to defense: concrete controls, an architecture framework that layers them, and a checklist to audit an existing agentic stack against.

Who it’s for

Security professionals, architects, and risk managers responsible for agentic AI systems that generate or execute code — anywhere a prompt could become an instruction to your infrastructure.

OWASP ASI05 — Unexpected Code Execution: Defense Architecture Technical Reference

March 9, 2026

Related research