OWASP ASI01–10 security sweep mapped to specific MiCA articles and SEC autonomous-agent guidance. Output is a cryptographically signed report (HMAC + ProofDB) attachable directly to your legal opinion.
| ASI | Category | Maps to |
|---|---|---|
| ASI01 | Prompt Injection | MiCA Title V Art. 60 (operational resilience) |
| ASI02 | Sensitive Information Disclosure | MiCA Title V Art. 64 (records of services/activities) |
| ASI03 | Supply Chain Vulnerabilities | MiCA Title V Art. 65 (outsourcing) · SEC autonomous-agent guidance §III.B |
| ASI04 | Data & Model Poisoning | MiCA Title III Art. 21 (qualified holdings / data integrity) |
| ASI05 | Improper Output Handling | MiCA Title V Art. 60(7) (effective internal control) |
| ASI06 | Excessive Agency | MiCA Title V Art. 67 (conflicts of interest) · UETA §202 (agency) |
| ASI07 | System Prompt Leakage | GDPR Art. 32 (security of processing) |
| ASI08 | Vector & Embedding Weaknesses | MiCA Title V Art. 67 (record retention) |
| ASI09 | Misinformation | MiCA Title V Art. 60(4) (transparency obligations) |
| ASI10 | Unbounded Consumption | MiCA Title V Art. 60 (operational resilience) · SEC §V.A (cost controls) |
Mappings shipped on Apache-2.0; law-firm white-labels can extend or override per jurisdiction. Each MASSAT report includes the mapping table appendix with your specific findings cross-linked.
We run MASSAT against our own marketplace every release. Current score is 4.3/10 — public, dated, signed, and below industry median. Why publish it? Because a credible auditor publishes their own report card. If you want to see what a real MASSAT report looks like, that's our own — same template, same signatures, same cross-walk.
Available on request: email [email protected]
No NDAs to start. Send an email with your contract's GitHub link or PDF, and we open a private project channel.