common-llm-security

Audits AI applications for OWASP LLM Top 10 security risks.

Updated Jun 25, 2026
One-click install
npx skills add https://github.com/VSF-QC-TTS/vf-qc-copilot --skill common-llm-security-vsf-qc-tts
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: common-llm-security
Source: https://github.com/VSF-QC-TTS/vf-qc-copilot/tree/main/.agents/skills/common/common-llm-security
Command: npx skills add https://github.com/VSF-QC-TTS/vf-qc-copilot --skill common-llm-security-vsf-qc-tts

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill unit provides a security checklist for AI applications based on the OWASP LLM Top 10 (2025) to ensure the safety and security of AI systems.

Core Features & Use Cases

  • Security Auditing: Identifies common security issues in AI applications like prompt injection, sensitive information disclosure, and data poisoning.
  • Agent Security: Checks for excessive agency, system prompt leakage, and vector store vulnerabilities.
  • Misinformation & Consumption: Ensures the reliability of LLM outputs for critical decisions and manages consumption without unbounded tokens.

Quick Start

Use the 'common-llm-security' skill to perform a security review on your AI application.

Frequently Asked Questions about common-llm-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my AI application for OWASP LLM Top 10 security risks?

You can audit for OWASP LLM Top 10 security risks by running a security checklist that checks your AI application for prompt injection, sensitive information exposure, and supply chain vulnerabilities to ensure proper data protection protocols are in place.

What is included in an LLM security checklist for AI systems?

An LLM security checklist includes auditing for prompt injection, sensitive information disclosure, data poisoning, excessive agency, system prompt leakage, and vector store vulnerabilities. It also verifies output reliability for critical decisions and manages unbounded token consumption.

How do I prevent prompt injection and system prompt leakage in my AI applications?

Prevent prompt injection and system prompt leakage by applying an LLM security checklist that identifies these specific vulnerabilities during a security audit. This validates that proper security protocols and data protection mechanisms are actively enforced across your AI systems.

Does the OWASP LLM Top 10 checklist cover agent security and excessive agency vulnerabilities?

Yes, the OWASP LLM Top 10 checklist covers agent security by explicitly checking for excessive agency, system prompt leakage, and vector store vulnerabilities. It ensures AI agents operate within secure boundaries and maintain proper data protection.

What's the best way to check for supply chain issues in LLM systems?

The best way to check for supply chain issues is performing a dedicated LLM security audit using the OWASP Top 10 checklist. This identifies supply chain vulnerabilities alongside other AI system risks, ensuring comprehensive security protocols and data protection are established.