/** * OWASP Agentic AI Top 10 (2026) — coverage matrix and verifier. * * Maps each OWASP Agentic risk category to the deterministic Network-AI control * that addresses it, and provides an `agt verify`-style coverage report. Unlike * the Python-skill MAESTRO/ASI table in `SKILL.md` (which scopes the bundled * scripts), this matrix covers the **TypeScript orchestration engine**. * * The controls referenced here are existing engine features — not aspirational * roadmap items. This module is a single source of truth for the README/SKILL * compliance section and for programmatic verification in CI. * * @module OwaspCompliance * @version 1.0.0 * @license MIT */ /** Coverage state for a single risk. */ export type CoverageStatus = 'covered' | 'partial' | 'not-applicable'; /** One OWASP Agentic risk and the controls that address it. */ export interface OwaspControl { /** Risk identifier, e.g. `ASI-01`. */ id: string; /** Risk name. */ risk: string; /** Coverage state. */ status: CoverageStatus; /** Deterministic controls (with the modules that implement them). */ controls: string[]; } /** Aggregate coverage report from {@link verifyOwaspCoverage}. */ export interface OwaspCoverageReport { total: number; covered: number; partial: number; notApplicable: number; controls: OwaspControl[]; /** `true` when every applicable risk is at least `partial` (no gaps). */ allAddressed: boolean; } /** * The OWASP Agentic AI Top 10 (2026) mapped to Network-AI engine controls. */ export declare const OWASP_AGENTIC_TOP10_2026: readonly OwaspControl[]; /** * Build a coverage report from a control matrix. * * @param controls The matrix to verify (defaults to {@link OWASP_AGENTIC_TOP10_2026}). * @returns Counts plus `allAddressed` (no `not-applicable`-excluded gaps). */ export declare function verifyOwaspCoverage(controls?: readonly OwaspControl[]): OwaspCoverageReport; /** * Render a coverage report as an `agt verify`-style text block. * * @param report A report from {@link verifyOwaspCoverage}. */ export declare function formatOwaspReport(report: OwaspCoverageReport): string; //# sourceMappingURL=owasp-compliance.d.ts.map