Skip to content

Add LLM VRT Entries #377

@drunkrhin0

Description

@drunkrhin0

Add VRT entries for LLMs based on the OWASP LLM Top 10 v1.1

Add to the following existing categories:

  • P1: Sensitive Data Exposure > Disclosure of Secrets > LLM Output Handling
  • Varies: Application Level DoS > Excessive Resource Consumption > Injection (Prompt)

Add a LLM Security Misconfiguration category:

  • P1: LLM Security Misconfiguration > Prompt Injection
  • P1: LLM Security Misconfiguration > Training Data Poisoning
  • P2: LLM Security Misconfiguration > Excessive Agency > Permission Manipulation via LLM
  • P4: LLM Security Misconfiguration > Insecure Application Logic > Overreliance on LLM Output

I've prepared an updated json file with the relevant changes pending approval and creating a PR - Branch

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions