OWASP/wstg

Proposal: Add a New Chapter for Testing LLM Applications

オープン

#1,447 opened on 2026/07/26

 (3 件のコメント) (0 件のリアクション) (0 人の担当者) (1,624 件のフォーク)github user discovery
help wantednew

Repository metrics

Stars
 (9,439 個のスター)
PR merge metrics
 (平均マージ 24d 19h) (30d で 22 merged PRs)

説明

I'd like to propose adding a new chapter to the WSTG, tentatively titled 4.13 Testing LLM Applications.

As Generative AI and Large Language Models (LLMs) are increasingly integrated into web applications, the WSTG currently lacks dedicated guidance for assessing these features from a web application penetration testing perspective.

This chapter would provide practical testing guidance aligned with the OWASP Top 10 for LLM Applications.

Proposed initial structure:

  • 4.13.1 Testing for Prompt Injection (Direct and Indirect)

  • 4.13.2 Testing for Sensitive Information Disclosure

  • 4.13.3 Testing for Insecure Output Handling

  • 4.13.4 Testing for Excessive Agency and Tool Abuse

  • Assign me, please!

コントリビューターガイド