OWASP / OWASP/DevGuide

Page on Top 10 for Large Language Model Applications

Open
#108 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement version-4.2.1
Dominant language
No language data
Stars
2.2k
Forks
407
PR merge metrics
No merged PRs in 30d

Description

Describe what content should be added :
It would be good to add a page on the OWASP Top 10 for Large Language Model Applications / LLM Top 10

Also consider other OWASP GenAI Security Project efforts:

It may be that the Top 10 page in Foundations should be expanded to have a page on the 'other' Top 10s:

  • API Security Top 10
  • Data Security Top 10
  • Low-Code/No-Code Top 10
  • Mobile Top 10
  • Serverless Top 10
  • Top 10 CI/CD Security Risks
  • Top 10 for Large Language Model Applications
  • Top 10 Privacy Risks
  • Top 10 Proactive Controls
  • Top 10 Web Application Security Risks

Context :
Section: 02-foundations/05-top-ten

Please be sure to follow the Contributing guide and in particular the Page structure

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in 02-foundations/05-top-ten and read the Contributing guide's Page structure section. Review the linked OWASP LLM Top 10 and related GenAI resources, then determine whether to add a dedicated page or expand the existing Top 10 coverage. Done means the relevant OWASP content is documented in the section and follows the required page structure.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.