iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Prompt injection is one way to manipulate an LLM application—not the whole security problem. Risk also comes from the data a system can access, the identities and tools it uses, the components it depends on, what happens to its outputs, and how much time and money it can consume. A useful security review follows those paths from input to consequence, rather than treating the model prompt as the security boundary.
Use OWASP’s 2025 Top 10 as a map, not a complete threat model
The OWASP Gen AI Security Project’s 2025 Top 10 for LLM and GenAI applications groups risks into ten categories. The list helps teams identify areas to examine, but it does not replace an architecture-specific threat model: a risk matters differently depending on the data, tools, users, and operational limits of a particular application.
| Category | What to examine |
|---|---|
| LLM01: Prompt Injection | Can user input or content the system consumes change model behavior in unintended ways? |
| LLM02: Sensitive Information Disclosure | Could private or regulated information be exposed through responses, context, or connected data? |
| LLM03: Supply Chain | Can the provenance, integrity, licensing, and maintenance of models, data, packages, and deployment components be trusted? |
| LLM04: Data and Model Poisoning | Could manipulated data or model artifacts affect training, fine-tuning, or embeddings? |
| LLM05: Improper Output Handling | Could generated text, code, markup, links, or tool arguments cause unsafe behavior in another component? |
| LLM06: Excessive Agency | What functions and connected systems can the model affect, and under whose authority? |
| LLM07: System Prompt Leakage | Does the design mistakenly rely on keeping prompts secret or on prompt text to enforce permissions? |
| LLM08: Vector and Embedding Weaknesses | Could the retrieval and embedding infrastructure or the data it indexes create security exposure? |
| LLM09: Misinformation | Could incorrect output mislead users or affect consequential decisions? |
| LLM10: Unbounded Consumption | Can excessive or repeated inference exhaust resources, degrade service, increase cost, or enable model extraction? |
These categories can overlap in one failure chain. For example, a manipulated document may influence a model, which then produces an unsafe link or invokes a tool with access to private data. Reviewing only the initial prompt would miss the downstream permissions and output handling that determine the impact.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →How prompt injection becomes an application risk
OWASP defines prompt injection as input that changes a model’s behavior or output in unintended ways. A direct attack arrives in a user prompt; an indirect attack is embedded in content the application consumes, such as a file or webpage. Instructions can affect a model even when they are not apparent to a person reading the content. Jailbreaking is a form of prompt injection aimed at getting a model to disregard safety protocols.
#1 Best Overall
Retrieval-augmented generation (RAG) and fine-tuning do not fully mitigate prompt injection. The practical question is what an influenced model can reach or do. A text-only drafting tool has a different consequence profile from an agent that can read internal files, access private stores, send email, call functions, or influence a high-impact decision.
OWASP identifies possible outcomes including sensitive-information disclosure, unauthorized function access, commands in connected systems, and manipulated decisions. A useful risk chain is therefore: untrusted content influences the model; the model produces a response or tool call; an application component accepts it; and an accessible data source or connected system turns it into an effect.
Reduce the impact instead of assuming perfect prevention
OWASP says fool-proof prevention is unclear. Its recommended mitigations focus on reducing the chance or impact of a successful attack:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →- Keep untrusted content clearly separated from trusted instructions and data.
- Constrain model behavior and validate output formats before another component consumes them.
- Use input and output filters as risk-reduction measures, not guarantees.
- Give tools and data connections only the privileges the task requires.
- Require human approval for high-risk operations.
- Run regular adversarial tests against the full application path, including indirect inputs.
Protect sensitive information across the application
Sensitive information at risk may include personal, financial, health, confidential business, credential, legal, or proprietary model information. It can be exposed in a model response or through application context, including when users submit sensitive content that is later surfaced to someone who should not see it.
A prompt instruction such as “do not reveal confidential data” is not an access-control boundary. Pair model-level guidance with controls around the data itself: sanitize and validate inputs, restrict the sources and records the application can retrieve, apply least privilege, and define clear retention and usage policies. Differential privacy and tokenization or redaction can be useful techniques in suitable settings, but no single technique is a universal remedy.
Review models, data, and dependencies as a supply chain
An LLM application depends on more than its model provider. Its supply chain can include third-party pretrained models and datasets, licenses, conventional software packages, and components used to develop and deploy the system. A vulnerability in a conventional dependency and a tampered model or dataset are different problems, but both make provenance and integrity relevant to security.
Rank #3
Data and model poisoning is a separate OWASP category. In practice, it can intersect with supply-chain review: poisoning concerns manipulated training, fine-tuning, or embedding data, while supply-chain review asks where artifacts came from and whether their integrity and provenance can be trusted. Teams should track the model and data versions they deploy, their origins, maintenance status, and whether the applicable licenses permit their use and distribution.
Treat model output as untrusted input
Generated text, code, markup, links, and tool arguments can cross into software that interprets or acts on them. If a downstream component renders, executes, follows, or otherwise trusts that output without suitable checks, the model’s response can become a path to an unintended effect. OWASP names this area improper output handling.
OWASP’s Q1 2026 exploit roundup, published April 14, 2026, describes a reported case in which output rendering became an exfiltration channel and recommends hardening URL validation and restricting outbound rendering. That example illustrates a system-boundary risk; the roundup is a curated, non-exhaustive discussion, not a complete incident dataset or a measure of incident frequency.
Rank #4
Keep agency and authorization outside the model
Agency is the ability an application gives a model or agent to call functions or affect connected systems. The more consequential those actions are, the more important it is to limit the model’s authority and independently check every action. A model should not be asked to decide whether it is allowed to access a record or execute an operation when the application can enforce that decision deterministically.
- Grant each tool and identity only the permissions needed for its task.
- Enforce authorization in the application or connected service, independently of model output.
- Use human review for high-impact actions.
- Set bounds on what actions can be taken and how many can be queued or executed.
OWASP’s Q1 2026 roundup maps reported privilege-abuse and data-leak cases to excessive agency and sensitive information disclosure. Its broader lesson is that identity, orchestration, and permissions can be part of an LLM security failure, alongside prompt manipulation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Do not use the system prompt as a secret or a permission system
OWASP Gen AI Security Project’s LLM07:2025 guidance states: “It’s important to understand that the system prompt should not be considered a secret, nor should it be used as a security control.” A prompt can be disclosed; placing credentials, connection strings, role definitions, or permission structures in it can expose information useful for follow-on attacks. Keep secrets in appropriate external systems and enforce privilege separation and authorization checks outside the LLM.
Best Value
Include retrieval, correctness, and availability in the review
Vector and embedding weaknesses
For systems using RAG or other embedding-based methods, retrieval infrastructure and indexed data belong in the threat model. Consider what information is represented in the index, who and what can retrieve it, and how retrieval results influence model responses. OWASP lists vector and embedding weaknesses as a distinct category; the relevant exposure depends on the system’s retrieval and data design.
Misinformation
OWASP includes misinformation because application users may rely on model outputs that are incorrect. Whether that is a security concern depends on the use case and consequence: an inaccurate draft is not automatically a security incident, but an error used in a consequential decision warrants suitable human review and safeguards.
Unbounded consumption
Uncontrolled inference can contribute to denial of service, service degradation, economic loss, or model extraction. Risk paths include unusually long or numerous inputs, high request volumes, expensive queries, and repeated API access. OWASP recommends bounding input size, applying rate limits and user quotas, managing resource allocation, setting timeouts, sandboxing, logging and anomaly detection, and limiting queued and total actions. Availability and cost controls are therefore part of security planning, not merely performance tuning.
Free tools Windows power users keep installed
One-click scans. No signup required.
What an LLM security assessment should cover
Use these questions to compare deployment designs and identify where to test. They are practical review axes derived from the OWASP categories, not an OWASP scoring rubric.
- Data exposure: What sensitive data can the model, retrieval system, tools, logs, and users reach?
- Privilege and agency: Which functions can be called, under whose identity, and which actions require an independent authorization check or human approval?
- Untrusted input paths: Which prompts, retrieved documents, webpages, files, images, or other inputs can influence model behavior?
- Supply-chain integrity: Which models, datasets, packages, and deployment components are used, and what is known about their provenance, maintenance, integrity, and licensing?
- Output effects: Can generated text, code, links, markup, or tool arguments trigger execution, external requests, or consequential decisions?
- Operational limits: Are request volume, input size, runtime, cost, queued actions, and outbound access bounded and monitored?
Test the complete path from input through retrieval and model response to validation, authorization, and any external action. OWASP’s Q1 2026 roundup reports incidents from January through early April 2026 and explicitly describes itself as non-exhaustive; it maps cases across categories but does not establish overall prevalence rates. OWASP also describes DonkAI as a hands-on lab with challenges for the 2025 Top 10 categories for readers who want to explore scenarios.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

