AIXYRA
All Frameworks
Security & resilienceCommunity security standard, actively maintained. The reference list of LLM application risks.

OWASP LLM Top 10

OWASP Top 10 for Large Language Model Applications

The security community's canonical list of LLM application risks — prompt injection, insecure output handling, supply chain, excessive agency, and more.

10 individual requirements seeded and assessable in AIXYRA.

The OWASP Top 10 for LLM Applications catalogs the security risks specific to systems built on large language models: prompt injection, insecure output handling, training data poisoning, model denial of service, supply-chain vulnerabilities, sensitive information disclosure, insecure plugin design, excessive agency, overreliance, and model theft. It has become the shared vocabulary between security teams and AI builders.

The list's recurring theme is agency and access: what an LLM application is allowed to reach — tools, data sources, downstream systems — determines the blast radius when something like prompt injection succeeds. Managing that means knowing and governing every tool and connection an AI system holds, not just testing the model.

Who it applies to

Security and engineering teams building or operating LLM-powered applications and agents — and governance teams setting the guardrails those teams work within.

Key requirement themes

Prompt injection & output handling

Untrusted input steering model behavior, and model output flowing unsanitized into downstream systems.

Excessive agency

Agents holding more tools, permissions, and autonomy than their purpose requires — the risk grows with each connection.

Supply chain

Risks inherited from base models, plugins, MCP servers, and third-party components.

Sensitive information disclosure

Models and agents leaking data they were trusted with — a data governance problem as much as a model one.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • Tool, MCP server, and data source registries make each agent's reach explicit — the inventory excessive-agency review requires
  • Governance checkgates approve every tool and MCP connection before an agent uses it in production
  • Dependency graphs expose the supply chain behind each AI system, with risk propagated along it
  • Assessments against seeded OWASP LLM Top 10 articles bring security review into the same evidence trail as compliance

OWASP LLM Top 10 FAQ

Is the OWASP LLM Top 10 a compliance framework?

It is a community security standard rather than a regulation — but it is the reference point security reviews, customers, and auditors use for LLM application risk, and treating it as an assessable framework turns ad hoc security review into tracked evidence.

How does AIXYRA address excessive agency?

By making agency visible and governed: every tool, MCP server, and data source an agent can reach is a registered, approved entity, dependency graphs show the full reach, and assessments against the seeded OWASP articles record that the review actually happened.

Assess your AI systems against OWASP LLM Top 10

OWASP LLM Top 10 ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.