OWASP Top 10 for LLM Applications
The security community's list of the most serious risks in LLM applications, including prompt injection, sensitive data disclosure, excessive agency, vector store weaknesses and unbounded consumption. Each entry explains the failure and the mitigations, which makes it a practical checklist before anything with tools or retrieval goes live.
Guide
AI & Machine Learning
OWASP
Intermediate
Free
The security community's list of the most serious risks in LLM applications, including prompt injection, sensitive data disclosure, excessive agency, vector store weaknesses and unbounded consumption. Each entry explains the failure and the mitigations, which makes it a practical checklist before anything with tools or retrieval goes live.
Ready to start?
Opens on OWASP in a new tab.
Stuck on something specific?
Writing only gets you so far. If you want an answer to your situation rather than the general case, book a session and we will work through it together. Sessions are free for approved Sefism members, and a few slots open each week.
Follow along
New writing, resources and project ideas land here first.