Compliance

OWASP® LLM Top 10

OWASP® LLM Top 10

DETAILS

The OWASP Top 10 for LLMs is a list of the most critical vulnerabilities found in applications utilizing LLMs. It was created to provide developers, data scientists, and security experts with practical, actionable, and concise security guidance to navigate the complex and evolving terrain of LLM security.

20%

compliant

456 Test Cases

72

Passed

384

Failed

LLM08: Excessive Agency

High Risk

DETAILS

Excessive Agency is the vulnerability that enables damaging actions to be performed in response to unexpected/ambiguous outputs from an LLM (regardless of what is causing the LLM to malfunction; be it hallucination/confabulation, direct/indirect prompt injection, malicious plugin, poorly-engineered benign prompts, or just a poorly-performing model). The root cause of Excessive Agency is typically one or more of: excessive functionality, excessive permissions or excessive autonomy. This differs from Insecure Output Handling which is concerned with insufficient scrutiny of LLM outputs.

ID

LLM08

Search for probe

Search

Status

All

PROBE

LAST RUN

STATUS

– No mapped Probes detected –