← Back to learn hub
LLM06

Excessive Agency

Agentic privilege escalation, unauthorized tool invocation, scope creep injection

What is Excessive Agency?

Excessive Agency is ranked LLM06 in the OWASP LLM Top 10 (2025) — the industry-standard taxonomy for large language model security risks. It represents one of the most commonly exploited vulnerability classes in production AI deployments.

How Nemesis tests for it

Excessive Agency

Agentic privilege escalation, unauthorized tool invocation, scope creep via instruction injection, autonomous action beyond intended permissions.

5 test casesNIST AC-3NIST AC-6NIST CM-7

Test your model for Excessive Agency

Run the full LLM06 attack suite against your LLM in minutes.

Run free scan →