OWASP/wstg

Proposal: Add a New Chapter for Testing LLM Applications

開放

#1,447 建立於 2026年7月26日

 (4 則留言) (0 個反應) (0 位負責人) (1,624 個分叉)github user discovery
help wantednew

倉庫指標

星標
 (9,439 顆星)
PR 合併指標
 (平均合併 24天 19小時) (30 天內合併 22 個 PR)

描述

I'd like to propose adding a new chapter to the WSTG, tentatively titled 4.13 Testing LLM Applications.

As Generative AI and Large Language Models (LLMs) are increasingly integrated into web applications, the WSTG currently lacks dedicated guidance for assessing these features from a web application penetration testing perspective.

This chapter would provide practical testing guidance aligned with the OWASP Top 10 for LLM Applications.

Proposed initial structure:

  • 4.13.1 Testing for Prompt Injection (Direct and Indirect)

  • 4.13.2 Testing for Sensitive Information Disclosure

  • 4.13.3 Testing for Insecure Output Handling

  • 4.13.4 Testing for Excessive Agency and Tool Abuse

  • Assign me, please!

貢獻者指南