الدرس 4 من 9 · 8 دقيقة
The OWASP Top 10 for LLM Applications (and its agentic sibling)
Learn the ten vulnerability categories in the 2025 OWASP LLM list, study prompt injection and excessive agency in depth, and see how the list maps to ATLAS.
هذه الصفحة متاحة بالإنجليزية حاليًا.
Where ATLAS describes how an attacker moves, the OWASP Top 10 for Large Language Model Applications describes what is weak. It is maintained by the OWASP GenAI Security Project, and its current edition on the project site is the 2025 list. It is a ranked catalogue of vulnerability categories, which makes it the most practical checklist for anyone building or testing an application around an LLM. It is a list of categories, not a test method: each entry still has to be turned into concrete tests for your system.
The 2025 list
| ID | Category | Closest ATLAS technique (examples) |
|---|---|---|
| LLM01:2025 | Prompt Injection | LLM Prompt Injection, direct and indirect (AML.T0051); LLM Jailbreak (AML.T0054) |
| LLM02:2025 | Sensitive Information Disclosure | Exfiltration techniques such as Exfiltration via AI Agent Tool Invocation (AML.T0086) |
| LLM03:2025 | Supply Chain | Case studies such as Compromised PyTorch Dependency Chain (AML.CS0015) |
| LLM04:2025 | Data and Model Poisoning | RAG Poisoning (AML.T0070); the poisoning case studies |
| LLM05:2025 | Improper Output Handling | LLM Response Rendering (AML.T0077) |
| LLM06:2025 | Excessive Agency | AI Agent Tool Invocation (AML.T0053) |
| LLM07:2025 | System Prompt Leakage | Discover LLM System Information (AML.T0069) |
| LLM08:2025 | Vector and Embedding Weaknesses | RAG Poisoning (AML.T0070); RAG Credential Harvesting (AML.T0082) |
| LLM09:2025 | Misinformation | Case studies such as ChatGPT Package Hallucination (AML.CS0022) |
| LLM10:2025 | Unbounded Consumption | Limit AI Workload Resource Consumption (AML.M0036) is the matching mitigation |
Prompt injection: the entry to know best
OWASP defines a prompt injection vulnerability as one where user prompts alter the model’s behaviour or output in unintended ways, even through inputs that are imperceptible to humans, as long as the model parses them. It distinguishes two forms. Direct injection comes from the user’s own input. Indirect injection arrives through external content such as websites or files that the model is asked to process. Jailbreaking is described as a form of prompt injection in which the input makes the model disregard its safety protocols entirely.
Two statements from OWASP shape how you test. First, retrieval-augmented generation and fine-tuning make outputs more relevant, but research shows they do not fully mitigate prompt injection. Second, because of how models work, “it is unclear if there are fool-proof methods of prevention”, so the aim is to limit impact. Its listed measures include:
- constrain model behaviour and validate expected output formats with deterministic code;
- apply input and output filtering;
- enforce least privilege, giving the application its own API tokens and handling those functions in code rather than handing them to the model;
- require human approval for high-risk actions;
- segregate and identify external content so untrusted material has less influence;
- run adversarial testing and attack simulations, treating the model as an untrusted user to test trust boundaries and access controls.
The last item is the bridge to red teaming. OWASP’s own example scenarios include a support chatbot told to ignore its guidelines and send emails, a summariser that follows hidden instructions on a web page and leaks the conversation through an image URL, and a modified document in a retrieval repository that changes the model’s output. Each is a ready-made test case.
Excessive agency: when the model can act
OWASP says Excessive Agency occurs when an LLM-based system performs damaging actions in response to unexpected, ambiguous or manipulated model output, once developers let it call functions or use extensions. It names three root causes: excessive functionality (tools that do more than the application needs), excessive permissions (broader access rights than necessary) and excessive autonomy (no verification or approval for high-impact actions). The mitigations follow the causes: minimise extensions and their functions, avoid open-ended tools such as shell execution, run actions in the user’s context with minimal privileges, require human approval for significant actions, and enforce authorisation in downstream systems instead of relying on the model’s judgement.
That last point is the most testable claim in the whole list. A tester can ask, for every tool the model can call: if the model were fully controlled by an attacker, what is the worst thing this tool could do, and would any system outside the model stop it?
The agentic sibling
OWASP has also published a separate OWASP Top 10 for Agentic Applications for 2026, dated 9 December 2025. The project describes it as a globally peer-reviewed framework identifying the most critical security risks facing autonomous and agentic AI systems, developed with over 100 industry experts. If your system plans multi-step tasks, calls tools or coordinates with other agents, read that document alongside the LLM list. This lesson does not reproduce its ten entries, so read the official document directly before you rely on it.
أهم النقاط
- The 2025 OWASP LLM Top 10 lists ten categories from LLM01 Prompt Injection to LLM10 Unbounded Consumption.
- Direct and indirect prompt injection cannot be fully prevented, so limit what an injected instruction can do: least privilege, human approval, segregated content and adversarial testing.
- Excessive agency has three root causes (functionality, permissions, autonomy) and is best mitigated by authorising actions outside the model.
- OWASP publishes a separate Top 10 for Agentic Applications (2026) for systems that plan and act.
اختبر نفسك
1. Which OWASP LLM 2025 category covers a model that can call tools with broader permissions than its task needs?
- LLM03 Supply Chain
- LLM06 Excessive Agency — صحيح.
- LLM09 Misinformation
- LLM10 Unbounded Consumption
Excessive Agency names excessive functionality, excessive permissions and excessive autonomy as root causes of damaging actions taken via manipulated or unexpected model output.
2. What is an indirect prompt injection?
- A prompt typed by the user in the chat box
- Instructions hidden in external content (a web page, file or document) that the model processes — صحيح.
- A network attack on the API
- A jailbreak of the operating system
OWASP describes indirect injection as arising when the model accepts input from external sources such as websites or files whose content alters its behaviour.
3. Does retrieval-augmented generation solve prompt injection?
- Yes, entirely
- No: OWASP says research shows RAG and fine-tuning do not fully mitigate it — صحيح.
- Only for images
- Only when using a larger model
RAG and fine-tuning aim to make outputs more relevant and accurate, but OWASP notes they do not fully mitigate prompt injection vulnerabilities.
4. Where should authorisation for a high-impact action be enforced, according to OWASP’s excessive agency guidance?
- In the system prompt only
- In downstream systems, not by relying on the model’s judgement — صحيح.
- Nowhere, the model decides
- Only in the user interface
OWASP recommends implementing authorisation in downstream systems rather than relying on an LLM to decide whether an action is allowed.
جرّبها مع FireAI
طبّق هذا الدرس عمليًا على جهاز Mac الخاص بك.
- القواعد: تطبيق أو موقع أو نطاق أو IP أو نطاق عناوين، إلى الأبد أو حتى إعادة التشغيل — اكتب قاعدة دقيقة كعنوان واحد أو واسعة كنطاق كامل.
- تحقيق في اتصال — قرّر بالاستناد إلى الحقائق أمامك، لا إلى تحذير مبهم.
- خريطة العالم — اطّلع على الوجهة الحقيقية لبياناتك، لا مجرد اسم مضيف عليك البحث عنه بنفسك.
- Requests by country and upload spikes — See at a glance where your Mac talks to, and notice at once when it suddenly sends a lot of data somewhere.
- قوائم التهديد (اختيارية) — قارن حركة بياناتك ببيانات تهديد عامة دون إرسالها إلى أي مكان.
- أوضاع الأمان: المنزل، المقهى، الحذر الشديد، تحت الهجوم — واءم صرامة FireAI مع مكان جهاز الـ Mac فعليًا، بلمسة واحدة.
المصادر
- OWASP GenAI Security Project: LLM Top 10 (2025)
- OWASP GenAI: LLM01:2025 Prompt Injection
- OWASP GenAI: LLM06:2025 Excessive Agency
- OWASP GenAI: Top 10 for Agentic Applications for 2026
- MITRE ATLAS data release 2026.09 (YAML)
طبّق ذلك على جهاز Mac الخاص بك
جرّب كل الميزات مجانًا لمدة 17 يومًا، دون بطاقة.