Before you start
This guide follows the names and order of the OWASP Top 10 for LLM Applications, 2025 edition. The short explanations and implementation checks are Truva’s editorial guidance. Numbering is not a prediction of risk in your environment.
A model is only one part of an LLM application. Evaluate how inputs enter, which information retrieval exposes, how outputs are used, and what connected tools can do. Controls belong at those boundaries as well as in model evaluation.
Prompt Injection
Instructions in prompts or external content can steer the model away from the intended task.
Keep untrusted input from authorizing actions.
Test malicious retrieved content. Enforce tool permissions and sensitive-action approvals outside the model.
Sensitive Information Disclosure
An answer can expose information the recipient should not receive.
Limit sensitive information in context.
Minimize sensitive inputs, apply retrieval permissions, and review provider retention and logging settings.
Supply Chain
Third-party code, model artifacts, and data introduce dependencies that require review.
Verify models, packages, and providers.
Record versions and provenance. Isolate evaluation and prevent unreviewed dependencies from reaching production credentials.
Data and Model Poisoning
Manipulated data or model components can introduce unwanted behavior that ordinary use may not reveal.
Validate changes to training and data sources.
Control ingestion and update permissions; track provenance and compare evaluation results after changes.
Improper Output Handling
Model output becomes dangerous when downstream software treats it as safe code, markup, or commands.
Treat generated output as untrusted.
Validate output types and apply context-appropriate escaping. Never execute generated commands merely because the model produced them.
Excessive Agency
An agent can cause larger harm when it has unnecessary capabilities or can act without appropriate review.
Limit tools, permissions, and autonomy.
Prefer narrowly scoped tools and identities. Require approval for consequential actions and bound execution.
System Prompt Leakage
Hidden instructions may be disclosed. Their secrecy should not be the control protecting sensitive systems.
Keep secrets and authorization outside prompts.
Remove credentials and sensitive policy details from prompts. Enforce access rules in application code.
Vector and Embedding Weaknesses
Shared indexes can retrieve documents across access boundaries or surface manipulated material.
Make retrieval permission-aware.
Partition and filter by authorized identity; test cross-tenant retrieval and changes to document permissions.
Misinformation
A fluent answer can still be inaccurate, incomplete, or unsupported.
Verify important answers against evidence.
Evaluate on representative tasks, verify references, and require human review where incorrect answers could cause significant harm.
Unbounded Consumption
Expensive inputs or repeated model and tool calls can exhaust capacity and increase cost.
Bound requests, runtime, and spend.
Set quotas, token and step limits, timeouts, and budget alerts. Test behavior when limits are reached.
Turn findings into verified fixes.
Start with your most exposed or sensitive workflow. Confirm the issue, assign an owner, make a controlled change, and keep evidence from the retest. These checks are a starting point, not proof of complete security or compliance.
Discuss a security assessmentCategory names and order attributed to OWASP Top 10 for LLM Applications (2025). OWASP content is available under CC BY-SA 4.0. This article’s adaptation and infographic are offered under the same license; Truva’s trademarks are excluded.
Join the discussion
Page viewsWhat are you seeing in your AI or cloud environment? Share a question or a practical lesson.
Comments are reviewed before publication. Your display name and comment will be public if approved. Please leave out confidential or personal information.
Enable JavaScript to read and submit comments.

Truva Solutions · Security Hub