Focus 1
Prompt injection
Treat model input channels and retrieved content as untrusted.
LLM applications should be reviewed against OWASP LLM Top 10 style risks and application-specific data flows.
Focus 1
Treat model input channels and retrieved content as untrusted.
Focus 2
Limit data exposure in prompts, logs, traces, and completions.
Focus 3
Pin dependencies, vet models, and monitor plugins, tools, and prompt assets.
Focus 4
Constrain tool permissions and require confirmation for high-impact actions.
Focus 5
Do not let generated outputs bypass review where correctness has legal, financial, or safety consequences.