owasp-llm-top10

Identify security vulnerabilities in LLM applications using the OWASP Top 10 for LLM Apps 2025.

44|2|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/mastepanoski/claude-skills --skill owasp-llm-top10
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: owasp-llm-top10
Source: https://github.com/mastepanoski/claude-skills/tree/main/skills/owasp-llm-top10
Command: npx skills add https://github.com/mastepanoski/claude-skills --skill owasp-llm-top10

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill enables security professionals and AI teams to perform a formal OWASP Top 10 security assessment of LLM and GenAI applications, providing structured risk identification and remediation guidance.

Core Features & Use Cases

  • Comprehensive coverage of OWASP Top 10 risks for LLM apps (LLM01–LLM10), including prompt injection, data leakage, supply chain, poisoning, improper output handling, excessive agent autonomy, prompt leakage, vector weaknesses, misinformation, and unbounded consumption.
  • Step-by-step audit workflow with intake, threat modeling, vulnerability scoring, and actionable reporting suitable for pre-deployment reviews and ongoing governance.
  • Use cases include security reviews of chatbots, RAG pipelines, and GenAI integrations across enterprise environments.

Quick Start

Initiate an OWASP LLM Top 10 security audit on your GenAI application to identify vulnerabilities and generate a prioritized mitigation plan.

Frequently Asked Questions about owasp-llm-top10

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OWASP Top 10 security audit for LLM applications?

An OWASP LLM security audit identifies vulnerabilities in GenAI applications through a structured workflow of intake, threat modeling, vulnerability scoring, and actionable reporting covering LLM01 through LLM10.

What security vulnerabilities should I check before deploying a RAG pipeline?

Before deploying a RAG pipeline, check for prompt injection, data leakage, supply chain risks, poisoning, improper output handling, vector weaknesses, misinformation, and unbounded consumption.

How do I mitigate prompt injection and data leakage in GenAI integrations?

Mitigate prompt injection and data leakage by conducting a formal OWASP Top 10 security assessment that provides structured risk identification and prioritized remediation guidance for enterprise GenAI integrations.

Can I use this OWASP Top 10 assessment for ongoing governance of AI assistants?

Yes, the OWASP Top 10 assessment applies to ongoing governance for AI assistants and chatbots, supporting continuous security reviews and structured vulnerability documentation across the application lifecycle.

Does this LLM security audit cover excessive agency and system prompt leakage?

Yes, the LLM security audit explicitly covers excessive agent autonomy and system prompt leakage, along with vector weaknesses and unbounded consumption, providing structured findings and remediation steps.

What is the best way to document risk in LLM and GenAI applications?

The best way to document LLM security risks is applying the OWASP Top 10 for LLM Apps 2025, which generates structured findings and prioritized mitigation plans for vulnerabilities like poisoning and misinformation.