1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →
What are the main security risks for LLM applications? Summarise the OWASP Top 10 for LLMs.
30-second answerSay your answer out loud first, then reveal.
| Risk | What it means | Example mitigation |
|---|---|---|
| LLM01 Prompt injection | Inputs (direct or via content) override instructions | Least privilege, isolation of untrusted content, HITL for sensitive actions |
| LLM02 Sensitive information disclosure | Model reveals PII, secrets, other users' data | Data minimisation, output filtering, access control in retrieval |
| LLM03 Supply chain | Compromised models, datasets, plugins, packages | Vetted sources, signatures, SBOM, pinned versions |
| LLM04 Data and model poisoning | Malicious data in training, fine-tuning or RAG corpora | Source trust, validation, monitoring |
| LLM05 Improper output handling | Using LLM output unsafely (XSS, SQL injection, command execution) | Treat output as untrusted; sanitise; parameterised queries |
| LLM06 Excessive agency | Agents with too many permissions or autonomy | Minimal tools and scopes, approvals |
| LLM07 System prompt leakage | Secrets or logic in prompts get exposed | Never put secrets in prompts; assume prompts are public |
| LLM08 Vector and embedding weaknesses | Cross-tenant leakage, poisoned or inverted embeddings | Permission-aware retrieval, tenant isolation |
| LLM09 Misinformation | Hallucinated or misleading output trusted by users | Grounding, citations, verification, UX warnings |
| LLM10 Unbounded consumption | Cost or DoS via huge or many requests | Rate limits, quotas, token caps |
Interview tip. Knowing the list is good; connecting each item to a concrete mitigation in your design is better.
Related
Slow is fine. Stopping is the only problem.