
ILT-U-4115
Generative AI (LLM) Application Security. In accordance with OWASP GenAI LLM Top 10 2026 and OWASP AIVSS v0.8 / ISO/IEC 17043
DETERMINATION | METHOD |
| LLM01 – Prompt Injection (F-01, F-02, F-12) | Apply crafted prompts to bypass system instructions; inject hidden instructions via RAG-retrieved documents; test Unicode homoglyph injection. Detection of direct and indirect prompt injection vulnerabilities. |
| LLM02 – Sensitive Information Disclosure (F-03) | Elicit memorized PII through repeated prompting; test information leakage in RAG responses. Detection of sensitive data exposure through LLM memorization. |
| LLM03 – Excessive Agency (F-04) | Craft tool-calling chains that trigger unauthorized actions (file deletion, database queries); test permission model. Detection of excessive permissions and unauthorized tool execution. |
| LLM04 – Supply Chain (F-13, F-16) | Review AI-BOM/SBOM for missing provenance; inspect requirements.txt for typosquatted dependencies. Detection of supply chain and dependency risks. |
| LLM05 – Data and Model Poisoning (F-05, F-14) | Inject poisoned documents into RAG corpus; inspect chat-template file for unauthorized modifications. Detection of retrieval poisoning and template tampering. |
| LLM06 – Unbounded Consumption (F-06) | Craft prompts that cause token-amplification or reasoning loops; test resource limits. Detection of denial-of-service and resource exhaustion vulnerabilities. |
| LLM07 – Misinformation (F-07) | Request domain-specific facts; verify model citations against ground truth. Detection of confident hallucination and fabricated content. |
| LLM08 – Hidden Context Exposure (F-08) | Apply prompt engineering to extract system prompt and hidden instructions. Detection of system prompt leakage and hidden context exposure. |
| LLM09 – Vector and Embedding Weaknesses (F-09, F-15) | Test cross-tenant data leakage via shared vector index; inspect vector-store metadata for PII. Detection of vector-store isolation failures and embedding inversion. |
| LLM10 – Improper Output Handling (F-10, F-11) | Generate malicious markdown/HTML to test XSS; craft prompts that produce ANSI escape sequences. Detection of output sanitization failures (XSS, injection). |


