-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathowasp_llm_top_10.yaml
More file actions
133 lines (120 loc) · 4.72 KB
/
Copy pathowasp_llm_top_10.yaml
File metadata and controls
133 lines (120 loc) · 4.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
# AUTOGENERATED by linkml/scripts/build_finos_data.py.
# Source: docs/_data/owasp-llm.yml
# Format: ai-atlas-nexus Container YAML (RiskTaxonomy + Risk rows (OWASP Top 10 for LLM Apps).)
taxonomies:
- id: owasp-llm-top-10-2025
name: OWASP Top 10 for LLM Applications (2025)
description: >-
OWASP-published top-10 list of the most critical security risks facing applications
that use large language models, 2025 edition.
type: RiskTaxonomy
url: https://genai.owasp.org/
version: '2025'
hasDocumentation:
- owasp-llm-top-10
dateCreated: '2026-06-25'
documents:
- id: owasp-llm-top-10
name: OWASP Gen AI Security Project
description: >-
OWASP Generative AI Security Project landing page, host of the Top 10 for
LLM Applications risk list.
author: OWASP
url: https://genai.owasp.org/
dateCreated: '2026-06-25'
entries:
- id: owasp-llm-top-10-2025-llm01-2025
name: LLM01:2025 Prompt Injection
description: 'OWASP Top 10 for LLM Applications risk: LLM01:2025 Prompt Injection.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm01-prompt-injection/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm02-2025
name: LLM02:2025 Sensitive Information Disclosure
description: >-
OWASP Top 10 for LLM Applications risk: LLM02:2025 Sensitive Information Disclosure.
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm03-2025
name: LLM03:2025 Supply Chain
description: 'OWASP Top 10 for LLM Applications risk: LLM03:2025 Supply Chain.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm032025-supply-chain/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm04-2025
name: 'LLM04: Data and Model Poisoning'
description: 'OWASP Top 10 for LLM Applications risk: LLM04: Data and Model
Poisoning.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm05-2025
name: LLM05:2025 Improper Output Handling
description: 'OWASP Top 10 for LLM Applications risk: LLM05:2025 Improper Output
Handling.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm06-2025
name: LLM06:2025 Excessive Agency
description: 'OWASP Top 10 for LLM Applications risk: LLM06:2025 Excessive Agency.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm062025-excessive-agency/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm07-2025
name: LLM07:2025 System Prompt Leakage
description: 'OWASP Top 10 for LLM Applications risk: LLM07:2025 System Prompt
Leakage.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm08-2025
name: LLM08:2025 Vector and Embedding Weaknesses
description: >-
OWASP Top 10 for LLM Applications risk: LLM08:2025 Vector and Embedding Weaknesses.
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm09-2025
name: LLM09:2025 Misinformation
description: 'OWASP Top 10 for LLM Applications risk: LLM09:2025 Misinformation.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm092025-misinformation/
dateCreated: '2026-06-25'
- id: owasp-llm-top-10-2025-llm10-2025
name: LLM10:2025 Unbounded Consumption
description: 'OWASP Top 10 for LLM Applications risk: LLM10:2025 Unbounded Consumption.'
type: Risk
isDefinedByTaxonomy: owasp-llm-top-10-2025
hasDocumentation:
- owasp-llm-top-10
url: https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/
dateCreated: '2026-06-25'