Skip to content

standard

OWASP Top 10 for LLM Applications

OWASP's ranked list of the most critical security risks in applications built on large language models.

Current clusters

build1 publisher

Tool permissions set the maximum harm a hijacked security agent can do

Dev.to author dharani2d argues agent security depends on who picks the next tool call, citing Excessive Agency's rise from sixth to third at OWASP. The proposed control plane keeps identity, authorization, argument checks and approvals in deterministic code outside the model.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40