Systematization of open protection mechanisms for agent systems based on large language models and analysis of threat landscape coverage
Protection tools for agent systems based on large language models develop in a fragmented way. They exist as separate open-source projects, commercial products, and research publications, and there is no unified view of how completely they cover current threat classes. This work systematizes the protection mechanisms of agent systems and assesses how completely they cover the threat landscape. A two-axis classification is proposed, in which each mechanism is characterized by its architectural level of application and its nature of impact. Following a unified scheme, 46 mechanisms selected from a catalog of 118 repositories are described. A quantitative coverage map of threats and mechanisms is built against the OWASP Top 10 for Agentic Applications 2026 and the OWASP Top 10 for Large Language Model Applications 2025. A defensein-depth indicator is introduced. The set of mechanisms covers all 10 classes of agentic threats, but coverage depth is distributed unevenly. «Tool misuse» is covered most fully, while «memory poisoning», «insecure inter agent communication», and «compromised agents» remain structural gaps without a mature preventive tool. Typical misconceptions in selecting protection tools are identified, and a minimal set of protections for designing agent systems is proposed.


