ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
COMMUNITY DRAFT · VERSIONED · v0.2

The Embodied AI Security Top 10

A robot policy has its own attack surface, and it needs its own risk taxonomy. This is a versioned, community-draft list for vision-language-action policies — each entry with a definition, a real example, how Provael tests it (or why it is out of scope), mitigations, and a compliance mapping.

Cross-mapped to OWASP Agentic + LLM Top 10MITRE ATLASProvael covers 8 / 10EAI01 measured on SmolVLA

The ten risks

RELATIONSHIP TO OTHER TAXONOMIES

Complementary to RoboJailBench — not a rival.

RoboJailBench (Yeke, Zhou, Lin, Cai, Bianchi & Celik — Purdue University; arXiv:2605.19328v1) proposes an 18-category harm-outcome taxonomy — what harm results (collision, force violation, unauthorized capture). This list is an attack-mechanism taxonomy — how the system is attacked. One mechanism here produces many of their harms, and several entries (poisoning, injection, CPS, evaluation) are delivery mechanisms or meta-risks with no single harm counterpart. Two axes of the same problem — complementary, not competing.

Mapped against their 18 harm categories, Provael measures 2 covered, 5 partial, 9 not covered, and 2 out of scope by design — deliberately not a clean sweep. A crosswalk that claimed to cover all 18 would be measuring the wrong thing.

$ provael crosswalk --target robojailbench

Test your policy against the Top 10.

Run Provael locally and measure your own attack-success rate, or book a red-team assessment for an audit-ready evidence pack.